RULE(RULE ID:333653)

Rule General Information
Release Date: 2021-06-11
Rule Name: GitLab Graphql Mail Information Disclosure Vulnerability (CVE-2020-26413)
Severity:
CVE ID:
Rule Protection Details
Description: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, Others
Reference: https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26413.json
https://hackerone.com/reports/972355
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26413.json