MEDIUM
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2
Published Mar 28, 2022
5.3
MEDIUMCVSS 3.1
EPSS 80.00%
Description
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.
Affected products
-
- Version >=13.0, <14.6.5StatusaffectedConstraints-
- Version >=14.7, <14.7.4StatusaffectedConstraints-
- Version >=14.8, <14.8.2StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-34051 Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4191.json x_refsource_CONFIRMVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/343898 x_refsource_MISCBroken Link
- https://hackerone.com/reports/1089609 x_refsource_MISCPermissions RequiredThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-34051 | Advisory | |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4191.json | x_refsource_CONFIRMVendor Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/343898 | x_refsource_MISCBroken Link | |
| https://hackerone.com/reports/1089609 | x_refsource_MISCPermissions RequiredThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Mar 28, 2022
Updated Aug 3, 2024
Reserved Dec 30, 2021
Link CVE-2021-4191
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2021-34051 Assigner GitLab
Published Mar 28, 2022
Updated Aug 3, 2024
Exploited since n/a
Link EUVD-2021-34051