MEDIUM

CVE-2021-4191

Gitlab GitLab 2022-03-28 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.

Summary dbcve.org

The GitLab GraphQL API in versions 13.0 through 14.8.2 allows unauthenticated user enumeration on private instances with restricted sign-ups. Attackers can query the GraphQL endpoint to discover valid usernames, potentially facilitating brute-force attacks or reconnaissance.

Mitigation

Upgrade GitLab to version 14.9.0, 14.8.5, 14.7.5, or 14.6.6 or later. Alternatively, restrict unauthenticated access to the GraphQL API endpoint at the load balancer or firewall level.

EPSS Score

80%
Probability of exploitation in next 30 days
99.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE