Vulnerabilities in GitLab

1,129 results
Vexday analysis

Com 1.068 CVEs catalogadas e 78 novas surgidas nos últimos 90 dias, o GitLab apresenta um volume de vulnerabilidades que exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com 4 CVEs confirmadas em uso por agentes de ameaça, mas a presença de 83 vulnerabilidades com prova de conceito pública e 24 de severidade crítica amplia consideravelmente a superfície de risco. O destaque mais preocupante é CVE-2021-22205, atualmente a CVE mais perigosa em exploração ativa, com EPSS de 0,9973 — valor que indica probabilidade altíssima de exploração —, e cuja falha de tipo mais recorrente na plataforma, CWE-770 (alocação de recursos sem limites adequados), sugere atenção redobrada a controles de validação de entrada e gestão de recursos. Equipes de segurança devem priorizar a remediação das CVEs com PoC disponível e manter rastreamento próximo das novas emissões, dado o ritmo relevante de descobertas recentes.

CVE-2021-39871MEDIUMIn all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import enabled is bypassed EPSS 0.9%CVE-2020-13325HIGHA vulnerability was discovered in GitLab versions prior 13.1. The comment section of the issue page was not restricting the characters propeEPSS 0.9%CVE-2022-2456MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versioEPSS 0.9%CVE-2022-1100MEDIUMA potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 1EPSS 0.9%CVE-2021-22226MEDIUMUnder certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since versiEPSS 0.9%CVE-2022-0549MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versioEPSS 0.9%CVE-2023-0632MEDIUMInefficient Regular Expression Complexity in GitLabEPSS 0.9%CVE-2023-3900MEDIUMImproper Validation of Specified Type of Input in GitLabEPSS 0.9%CVE-2021-39944HIGHAn issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 beforeEPSS 0.9%CVE-2022-0390MEDIUMImproper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retriEPSS 0.9%CVE-2022-0093LOWAn issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allEPSS 0.9%CVE-2020-13349MEDIUMAn issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a file path resulted inEPSS 0.9%CVE-2022-2281LOWAn information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 priorEPSS 0.9%CVE-2021-39945LOWImproper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 befoEPSS 0.9%CVE-2021-39939MEDIUMAn uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions stEPSS 0.9%CVE-2021-39934MEDIUMImproper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before EPSS 0.9%CVE-2021-39873MEDIUMIn all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to trick users into visitEPSS 0.9%CVE-2023-3424HIGHInefficient Regular Expression Complexity in GitLabEPSS 0.9%CVE-2022-3639MEDIUMA potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2EPSS 0.9%CVE-2022-3740MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 priorEPSS 0.9%