CVE-2021-22257

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 05:49

Type Values Removed Values Added
References () https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22257.json - Vendor Advisory () https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22257.json - Vendor Advisory
References () https://gitlab.com/gitlab-org/gitlab/-/issues/23832 - Broken Link () https://gitlab.com/gitlab-org/gitlab/-/issues/23832 - Broken Link

Information

Published : 2021-10-05 14:15

Updated : 2024-11-21 05:49


NVD link : CVE-2021-22257

Mitre link : CVE-2021-22257

CVE.ORG link : CVE-2021-22257


JSON object : View

Products Affected

gitlab

  • gitlab