CVE-2021-4191
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.
- Affected products
- Gitlab, Gitlab Ce/Ee
- Gitlab
- < 14.6.5, 14.7.4, 14.8.2
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 80.0% (100th percentile)
- NVD status
- Modified
- Published
- 2022-03-28
CVE-2021-4191 at NVD
6 known exploits for CVE-2021-4191
Proof-of-concept code and exploit modules indexed by Sploitus