CVE-2020-26416 log

Source
Severity Medium
Remote Yes
Type Information disclosure
Description
Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.
Group Package Affected Fixed Severity Status Ticket
AVG-1347 gitlab 13.6.1-1 13.6.2-1 Medium Not affected
References
https://about.gitlab.com/releases/2020/12/07/security-release-gitlab-13-6-2-released/#search-terms-logged-in-search-parameter-in-rails-logs
https://gitlab.com/gitlab-org/gitlab/-/issues/244495