漏洞描述
An unauthenticated remote attacker can leverage this vulnerability to collect registered GitLab usernames, names, and email addresses.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.rapid7.comhttps://www.rapid7.com/blog/post/2022/03/03/cve-2021-4191-gitlab-graphql-api-user-enumeration-fixed/↗thehackernews.comhttps://thehackernews.com/2022/03/new-security-vulnerability-affects.html↗cve.mitre.orghttps://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-4191↗gitlab.comhttps://gitlab.com/gitlab-org/gitlab/-/issues/343898↗gitlab.comhttps://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4191.json↗