An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.
No PoCs from references.
- https://github.com/0day404/vulnerability-poc
- https://github.com/20142995/Goby
- https://github.com/20142995/nuclei-templates
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ARPSyndicate/kenzer-templates
- https://github.com/ArrestX/--POC
- https://github.com/EdgeSecurityTeam/Vulnerability
- https://github.com/H4ckTh3W0r1d/Goby_POC
- https://github.com/HimmelAward/Goby_POC
- https://github.com/KayCHENvip/vulnerability-poc
- https://github.com/Kento-Sec/GitLab-Graphql-CVE-2020-26413
- https://github.com/Miraitowa70/POC-Notes
- https://github.com/NyxAzrael/Goby_POC
- https://github.com/SexyBeast233/SecBooks
- https://github.com/Threekiii/Awesome-POC
- https://github.com/XiaomingX/awesome-poc-for-red-team
- https://github.com/Z0fhack/Goby_POC
- https://github.com/d4n-sec/d4n-sec.github.io
- https://github.com/hktalent/bug-bounty
- https://github.com/kh4sh3i/Gitlab-CVE
- https://github.com/tzwlhack/Vulnerability