Vulnerability record · CVE-2021-4191 · published 28 March 2022
CVE-2021-4191: GitLab GraphQL API user enumeration on restricted-signup instances
Gitlab · Gitlab
GitLab CE/EE versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2 expose a user enumeration flaw in the GraphQL API. On private instances with restricted sign-ups, an unauthenticated attacker can determine which usernames exist. This matters because it leaks account information that can feed credential attacks or social engineering.
Description
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Automated analysis
medium priorityCVSS is medium (5.3) and impact is limited to information disclosure, but the very high EPSS and unauthenticated network reach make it worth prompt patching.
What it is
GitLab CE/EE versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2 expose a user enumeration flaw in the GraphQL API. On private instances with restricted sign-ups, an unauthenticated attacker can determine which usernames exist. This matters because it leaks account information that can feed credential attacks or social engineering.
Impact
An attacker gains confirmation of valid usernames on the target GitLab instance. No data beyond account existence is exposed, but it enables targeted follow-on attacks.
Attack surface
Reachable over the network through the GraphQL API with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The flaw only applies to private GitLab instances that have restricted sign-ups enabled.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented. EPSS is very high (0.80004 probability, 99.593 percentile), and references are vendor advisory, a broken issue link, and a HackerOne report marked Permissions Required, so no public exploit code is confirmed in this record.
What to do
- Upgrade GitLab CE/EE to a release after 14.6.5, 14.7.4, or 14.8.2 as applicable to your branch.
- If immediate upgrade is not possible, restrict network access to the GraphQL API to trusted users or networks.
- Review whether restricted sign-ups are required; disabling that configuration removes the described exposure.
- Monitor GitLab security advisories for the fixed release matching your version line.
Detection
- Alert on high-volume or automated GraphQL queries from unauthenticated sources, especially those probing user or username fields.
- Baseline normal GraphQL API request patterns and flag enumeration-like sequences from single IPs or sessions.
- Correlate GitLab authentication logs for failed logins using usernames that first appeared in GraphQL enumeration traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4191.json | Vendor Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/343898 | Broken Link |
| https://hackerone.com/reports/1089609 | Permissions RequiredThird Party Advisory |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4191.json | Vendor Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/343898 | Broken Link |
| https://hackerone.com/reports/1089609 | Permissions RequiredThird Party Advisory |
Track CVE-2021-4191 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-4191), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.