Medium severity5.3NVD Advisory· Published Mar 28, 2022· Updated Jun 17, 2026
CVE-2021-4191
CVE-2021-4191
Description
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.
Affected products
513.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2+ 3 more
- (no CPE)range: 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=13.0.0,<14.6.5
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=13.0.0,<14.6.5
- (no CPE)range: >=14.8, <14.8.2
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4191.jsonnvdVendor Advisory
- hackerone.com/reports/1089609nvdPermissions RequiredThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/343898nvdBroken Link
News mentions
0No linked articles in our index yet.