S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Misconfiguration·Updated Jan 3, 2024

GitLab - User Information Disclosure Via Open API Scanner

There is an user enumeration vulnerability via an incorrect authorisation check in Gitlab.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
Detail

Username enumeration is a type of vulnerability in web applications, where it is possible to find exact usernames or to confirm that a guessed (or leaked) username exists in the system based on system response.

The API users endpoint no longer requires authentication to fetch data on individual users. This allows fetching of user data on instances that do not allow public projects. Privately hosted instances (and dev) shouldn't allow unauthenticated requests to this endpoint.

Solution Advice
  • You have to update to the latest version.
  • Access restriction should be applied.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.