CVE-2021-4191: GitLab
Medium severity, CVSS 5.3. EPSS: 80% chance of exploitation in the next 30 days.
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.
Affected products
- GitLab GitLab: from 13.0.0, before 14.6.5 (fixed in 14.6.5); from 14.7.0, before 14.7.4 (fixed in 14.7.4); from 14.8, before 14.8.2 (fixed in 14.8.2)
Published 2022-03-28. Last modified 2026-06-17.