![CVE-2021-4191: GitLab GraphQL API User Enumeration (FIXED)](https://blog.rapid7.com/content/images/2022/03/gitlab-vuln.jpg) On February 25, 2022, GitLab [published a fix]() for CVE-2021-4191, which ...
Continue ReadingMay 30, 2022
Found **internal-graphql-stable-web-jer5f6d-n-933384777[.]us-eas...Read More ...
Continue ReadingMay 30, 2022
Found **graphql-server-ecs-chat-497780143[.]us-west-2.elb.crypto...Read More ...
Continue ReadingMay 30, 2022
Found **graphql[.]magical.coffee** in [RST Threat Feed](https:/...Read More ...
Continue ReadingMay 30, 2022
This module queries the GitLab GraphQL API without authentication to acquire the list of GitLab users (CVE-2021-4191). The module works on all GitLab versions from 13.0 up to 14.8.2, 14.7.4, and 14.6. ...
Continue ReadingMay 30, 2022
![Analyzing the Attack Landscape: Rapid7s 2021 Vulnerability Intelligence Report](https://blog.rapid7.com/content/images/2022/03/vuln-intel-report.jpg) Every year, our research team at Rapid7 analyz ...
Continue ReadingMay 30, 2022
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumerat ...
Continue ReadingMay 30, 2022
## CVE-2022-21999 - SpoolFool ![Metasploit Weekly Wrap-Up](https://blog.rapid7.com/content/images/2022/03/metasploit-ascii-1-2.png) Our very own [Shelby Pace]() has added a new module for the [CVE-202 ...
Continue ReadingMay 30, 2022
Back to Main