Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-4191

Опубликовано: 28 мар. 2022
Источник: debian
EPSS Критический

Описание

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitlabfixed14.6.5+ds1experimentalpackage
gitlabfixed15.10.8+ds1-2package

Примечания

  • https://about.gitlab.com/releases/2022/02/25/critical-security-release-gitlab-14-8-2-released/

EPSS

Процентиль: 100%
0.92906
Критический

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.

CVSS3: 5.3
nvd
почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.

CVSS3: 5.3
github
почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.

EPSS

Процентиль: 100%
0.92906
Критический