CVE-2021-22257

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 05:49

Type Values Removed Values Added
References () https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22257.json - Vendor Advisory () https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22257.json - Vendor Advisory
References () https://gitlab.com/gitlab-org/gitlab/-/issues/23832 - Broken Link () https://gitlab.com/gitlab-org/gitlab/-/issues/23832 - Broken Link

09 Oct 2021, 03:34

Type Values Removed Values Added
References (MISC) https://gitlab.com/gitlab-org/gitlab/-/issues/23832 - (MISC) https://gitlab.com/gitlab-org/gitlab/-/issues/23832 - Broken Link
References (CONFIRM) https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22257.json - (CONFIRM) https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22257.json - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 5.3
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*

05 Oct 2021, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-05 14:15

Updated : 2024-11-21 05:49


NVD link : CVE-2021-22257

Mitre link : CVE-2021-22257

CVE.ORG link : CVE-2021-22257


JSON object : View

Products Affected

gitlab

  • gitlab