Vulnerabilidades en GitLab

1129 resultados
Análisis Vexday

Com 1.068 CVEs catalogadas e 78 novas surgidas nos últimos 90 dias, o GitLab apresenta um volume de vulnerabilidades que exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com 4 CVEs confirmadas em uso por agentes de ameaça, mas a presença de 83 vulnerabilidades com prova de conceito pública e 24 de severidade crítica amplia consideravelmente a superfície de risco. O destaque mais preocupante é CVE-2021-22205, atualmente a CVE mais perigosa em exploração ativa, com EPSS de 0,9973 — valor que indica probabilidade altíssima de exploração —, e cuja falha de tipo mais recorrente na plataforma, CWE-770 (alocação de recursos sem limites adequados), sugere atenção redobrada a controles de validação de entrada e gestão de recursos. Equipes de segurança devem priorizar a remediação das CVEs com PoC disponível e manter rastreamento próximo das novas emissões, dado o ritmo relevante de descobertas recentes.

CVE-2026-0723HIGHUnchecked Return Value in GitLabEPSS 0.9%CVE-2021-22254LOWUnder very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE 13.1 and later throuEPSS 0.9%CVE-2022-2244MEDIUMAn improper authorization vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prEPSS 0.9%CVE-2021-39943MEDIUMAn authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versEPSS 0.9%CVE-2017-0925Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration APEPSS 0.9%CVE-2023-3385MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLabEPSS 0.9%CVE-2021-22236MEDIUMDue to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerEPSS 0.9%CVE-2021-39887HIGHA stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to exeEPSS 0.9%CVE-2025-12562HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.9%CVE-2022-0738MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting from 14.7 before 14.7.EPSS 0.9%CVE-2021-22180MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to accesEPSS 0.9%CVE-2022-0136MEDIUMA vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF EPSS 0.9%CVE-2021-22186MEDIUMAn authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricEPSS 0.9%CVE-2022-2512MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 beforeEPSS 0.9%CVE-2021-39932MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 beforeEPSS 0.9%CVE-2021-39931LOWAn issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 beforeEPSS 0.9%CVE-2022-1124MEDIUMAn improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior tEPSS 0.9%CVE-2022-2499LOWAn issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions starting from 15.1 before 1EPSS 0.9%CVE-2022-1545MEDIUMIt was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8EPSS 0.9%CVE-2022-2270LOWAn issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0EPSS 0.9%