Unrated severityNVD Advisory· Published Mar 28, 2022· Updated Aug 3, 2024
CVE-2021-4191
CVE-2021-4191
Description
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.
Affected products
3- Range: >=13.0, <=14.6.5 || >=14.7, <=14.7.4 || >=14.8, <=14.8.2
- Range: >=14.8, <14.8.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4191.jsonmitrex_refsource_CONFIRM
- gitlab.com/gitlab-org/gitlab/-/issues/343898mitrex_refsource_MISC
- hackerone.com/reports/1089609mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.