CVE-2021-4191
28.03.2022, 19:15
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.Enginsight
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 13.0.0 ≤ 𝑥 < 14.6.5 |
gitlab | gitlab | 13.0.0 ≤ 𝑥 < 14.6.5 |
gitlab | gitlab | 14.7.0 ≤ 𝑥 < 14.7.4 |
gitlab | gitlab | 14.7.0 ≤ 𝑥 < 14.7.4 |
gitlab | gitlab | 14.8 ≤ 𝑥 < 14.8.2 |
gitlab | gitlab | 14.8 ≤ 𝑥 < 14.8.2 |
𝑥
= Vulnerable software versions
References