CVE-2021-4191 is a user enumeration vulnerability affecting GitLab CE/EE versions 13.0 through 14.8.2. Unauthenticated attackers can leverage the GraphQL API to identify valid user accounts on private GitLab instances with restricted sign-ups. This medium-severity vulnerability has a CVSS score of 5.3, indicating low impact on confidentiality and no impact on integrity or availability, and is easily exploitable over the network without user interaction. While not listed on the KEV catalog, exploit modules for Metasploit and Nuclei are publicly available, and the vulnerability has garnered significant community discussion and media coverage, suggesting active awareness and potential exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.0.0, < 14.6.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 13.0.0, < 14.6.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 14.7.0, < 14.7.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 14.7.0, < 14.7.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 14.8, < 14.8.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.