Loading HuntDB...

GHSA-gh46-94pq-p4r3

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances.

Related CVEs

Key Information

GHSA ID
GHSA-gh46-94pq-p4r3
Published
May 24, 2022 7:16 PM
Last Modified
May 24, 2022 7:16 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 4, 2025 6:39 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.