Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GitLab | GitLab CE/EE | >=13.4, <13.4.7 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | GitLab-Graphql-CVE-2020-26413 POC | https://github.com/Kento-Sec/GitLab-Graphql-CVE-2020-26413 | POC Details |
| 2 | GitLab CE and EE 13.4 through 13.6.2 is susceptible to Information disclosure via GraphQL. User email is visible. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-26413.yaml | POC Details |
| 3 | None | https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/GitLab%20Graphql%E9%82%AE%E7%AE%B1%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E%20CVE-2020-26413.md | POC Details |
| 4 | GitLab Graphql邮箱信息泄露漏洞 CNVD-2021-14193 / CVE-2020-26413 | https://github.com/chaitin/xray-plugins/blob/main/poc/manual/gitlab-graphql-info-leak-cve-2020-26413.yml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-26417 | 5.3 MEDIUM | GitLab CE/EE 信息泄露漏洞 |
| CVE-2020-26408 | 5.3 MEDIUM | Gitlab CE/EE 信息泄露漏洞 |
| CVE-2020-26409 | 4.3 MEDIUM | Gitlab CE/EE 输入验证错误漏洞 |
| CVE-2020-26415 | 4.3 MEDIUM | GitLab 信息泄露漏洞 |
| CVE-2020-13357 | 4.3 MEDIUM | Gitlab CE/EE 安全漏洞 |
| CVE-2020-26411 | 4.3 MEDIUM | GitLab 安全漏洞 |
| CVE-2020-26416 | 4.0 MEDIUM | GitLab 信息泄露漏洞 |
| CVE-2020-26412 | 3.1 LOW | GitLab EE 信息泄露漏洞 |
No comments yet