Exposição de GitLab

Development, Issue trackers
337
score de exposição
486
sites usam
5
em exploração
27
críticos
Análise Vexday

Com 1.068 CVEs catalogadas e 78 novas vulnerabilidades registradas nos últimos 90 dias, o GitLab apresenta um volume de exposição que exige monitoramento contínuo. A taxa de exploração ativa — 4 entradas no catálogo KEV da CISA, representando 0,37% do total — está abaixo da média geral do catálogo (0,45%), embora esse dado não elimine a atenção necessária às falhas confirmadas. A vulnerabilidade CVE-2021-22205 concentra o maior risco imediato, com score EPSS de 0,9973, indicando altíssima probabilidade de exploração ativa, e deve ser tratada como prioridade absoluta em qualquer plano de remediação. O tipo de falha mais recorrente, CWE-770 (alocação de recursos sem limite ou controle), combinado com 24 vulnerabilidades de severidade crítica, sugere atenção estrutural às práticas de desenvolvimento e à gestão de recursos na plataforma.

CVEs

1.129 resultados
CVE-2022-3060HIGHImproper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attackeEPSS 1.0%CVE-2021-22206MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other mainEPSS 1.0%CVE-2021-39897LOWImproper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent groEPSS 1.0%CVE-2020-26408MEDIUMA limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 thatEPSS 1.0%CVE-2019-15579An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) where thEPSS 1.0%CVE-2021-22216MEDIUMA denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolleEPSS 1.0%CVE-2021-22259MEDIUMA potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.EPSS 1.0%CVE-2022-3478MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting from 15.5 before 15.5.EPSS 1.0%CVE-2020-13297LOWA vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. When 2 factor authentication was enabled for groups, a EPSS 1.0%CVE-2022-1120MEDIUMMissing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2EPSS 1.0%CVE-2022-1954MEDIUMA Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 prior to 14.10.5, 15.0 prior to 15.0.EPSS 1.0%CVE-2021-39936LOWImproper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4EPSS 1.0%CVE-2021-22172MEDIUMImproper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releasesEPSS 1.0%CVE-2019-15578An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). The patEPSS 1.0%CVE-2020-13263HIGHAn authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could alloEPSS 1.0%CVE-2021-39895MEDIUMIn all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project export so when an unEPSS 1.0%CVE-2020-26412LOWRemoved group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 1EPSS 1.0%CVE-2020-13285HIGHFor GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting (XSS) vulnerability exists in the issue reference number tooltip.EPSS 1.0%CVE-2022-3572CRITICALA cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, andEPSS 1.0%CVE-2020-13324MEDIUMA vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed viEPSS 1.0%