An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/343898 | broken link |
https://hackerone.com/reports/1089609 | third party advisory permissions required |
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4191.json | vendor advisory |