MEDIUM
CVE-2021-4191
CVSS
5.3
Description
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.
Summary dbcve.org
The GitLab GraphQL API in versions 13.0 through 14.8.2 allows unauthenticated user enumeration on private instances with restricted sign-ups. Attackers can query the GraphQL endpoint to discover valid usernames, potentially facilitating brute-force attacks or reconnaissance.
Mitigation
Upgrade GitLab to version 14.9.0, 14.8.5, 14.7.5, or 14.6.6 or later. Alternatively, restrict unauthenticated access to the GraphQL API endpoint at the load balancer or firewall level.
EPSS Score
80%
Probability of exploitation in next 30 days
99.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.