VYPR
Medium severity4.0NVD Advisory· Published Dec 11, 2020· Updated Jun 17, 2026

CVE-2020-26416

CVE-2020-26416

Description

Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

Affected products

5
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 2 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=8.4.0,<13.4.7
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=8.4.0,<13.4.7
    • (no CPE)range: >=8.4 to <13.4.7
  • Range: >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2
  • osv-coords
    Range: >= 8.4.0, < 13.4.7

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.