CVE-2020-26413
MEDIUMNuclei
Gitlab CE/EE 13.4 - 13.6.2 - Information Disclosure
Record summary
CVE-2020-26413 has a selected CVSS score of 5.3 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
GitLab CE/EEBrowse GitLab / GitLab CE/EE | CVE List | >=13.4, <13.4.7 | affected |
| >=13.5, <13.5.5 | affected | ||
| >=13.6, <13.6.2 | affected |
Proofs of concept
1Repository PoCs
GitHubKento-Sec/GitLab-Graphql-CVE-2020-26413Repository PoCby Kento-SecStars: 1Not analyzed2 files
Nuclei templates
1ProjectDiscoveryMEDIUMGitlab CE/EE 13.4 - 13.6.2 - Information DisclosureCVSS 5.3
GitLab CE and EE 13.4 through 13.6.2 is susceptible to Information disclosure via GraphQL. User email is visible. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Impact
An attacker can gain unauthorized access to sensitive information.
Remediation
Upgrade Gitlab CE/EE to version 13.6.3 or later.
WeaknessesCWE-200
Authors_0xf4n9x_, pikpikcu
Template tagscvecve2020hackeronegitlabexposureenumgraphqlvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
Shodan: http.title:"GitLab"
Shodan: cpe:"cpe:2.3:a:gitlab:gitlab"
Shodan: http.title:"gitlab"
FOFA: title="gitlab"
Google: intitle:"gitlab"
https://gitlab.com/gitlab-org/gitlab/-/issues/244275 https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26413.json https://nvd.nist.gov/vuln/detail/CVE-2020-26413 https://hackerone.com/reports/972355 https://github.com/ARPSyndicate/cvemon
Source: ProjectDiscovery
References
4gitlab.comConfirmation
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26413.json gitlab.com
https://gitlab.com/gitlab-org/gitlab/-/issues/244275 hackerone.com
https://hackerone.com/reports/972355 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-26413