Enhancement: cves/2021/CVE-2021-4191.yaml by mp
parent
aac30ad6ef
commit
81868f926d
|
@ -4,10 +4,11 @@ info:
|
|||
name: GitLab GraphQL API User Enumeration
|
||||
author: zsusac
|
||||
severity: medium
|
||||
description: A remote, unauthenticated attacker can use this vulnerability to collect registered GitLab usernames, names, and email addresses.
|
||||
description: An unauthenticated remote attacker can leverage this vulnerability to collect registered GitLab usernames, names, and email addresses.
|
||||
reference:
|
||||
- https://www.rapid7.com/blog/post/2022/03/03/cve-2021-4191-gitlab-graphql-api-user-enumeration-fixed/
|
||||
- https://thehackernews.com/2022/03/new-security-vulnerability-affects.html
|
||||
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-4191
|
||||
classification:
|
||||
cvss-metrics: CVSS:5.3/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
||||
cvss-score: 5.3
|
||||
|
@ -47,3 +48,5 @@ requests:
|
|||
- type: json
|
||||
json:
|
||||
- '.data.users.nodes[].username'
|
||||
|
||||
# Enhanced by mp on 2022/03/07
|
||||
|
|
Loading…
Reference in New Issue