S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-4191 Scanner

Detects 'User Enumeration' vulnerability in GitLab affects v. 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-4191
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
GitLabby GitLab
>=14.8, <14.8.2
Updated Aug 21, 2026View on NVD →
Detail

GitLab is an open-source Git repository management system that aids in the seamless deployment and management of software development projects. It offers a range of features, including in-built CI/CD support, project management tools, and code review options. GitLab is a modern, cloud-native solution that helps companies develop and deploy software quickly, efficiently, and securely.

Recently, a CVE-2021-4191 vulnerability has been detected in GitLab, affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. The issue revolves around private GitLab instances that have restricted sign-ups. This vulnerability could allow unauthenticated users to exploit the GraphQL API and perform user enumeration.

Exploiting the CVE-2021-4191 vulnerability could have severe consequences. It can lead to unauthenticated users gaining access to sensitive user data, such as usernames and email addresses, hosted on GitLab. Attackers may also use this information to launch further attacks on the company's infrastructure, leading to a potential data breach.

With the pro features of the s4e.io platform, readers can quickly and easily learn about vulnerabilities in their digital assets. They can access customized reports, obtain clear and concise guidance on fixing vulnerabilities, and stay up-to-date on the latest security threats. By using this platform, businesses can secure their digital assets with confidence and stay protected from malicious attacks.

 

REFERENCES

Solution Advice

To protect against the CVE-2021-4191 vulnerability, the following precautions can be taken:

  • Upgrade to the latest GitLab versions to fix the vulnerability.
  • Use a firewall to block unauthorized traffic from accessing the GitLab instance.
  • Enable two-factor authentication to better secure user accounts.
  • Perform a regular security audit to ensure that the GitLab instance is secure from further vulnerabilities.
  • Train all users to follow best security practices and maintain security awareness.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-4191 scanner - User Enumeration vulnerability in GitLab S4E