Vulnerabilidades em GitLab

1.129 resultados
Análise Vexday

Com 1.068 CVEs catalogadas e 78 novas surgidas nos últimos 90 dias, o GitLab apresenta um volume de vulnerabilidades que exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com 4 CVEs confirmadas em uso por agentes de ameaça, mas a presença de 83 vulnerabilidades com prova de conceito pública e 24 de severidade crítica amplia consideravelmente a superfície de risco. O destaque mais preocupante é CVE-2021-22205, atualmente a CVE mais perigosa em exploração ativa, com EPSS de 0,9973 — valor que indica probabilidade altíssima de exploração —, e cuja falha de tipo mais recorrente na plataforma, CWE-770 (alocação de recursos sem limites adequados), sugere atenção redobrada a controles de validação de entrada e gestão de recursos. Equipes de segurança devem priorizar a remediação das CVEs com PoC disponível e manter rastreamento próximo das novas emissões, dado o ritmo relevante de descobertas recentes.

CVE-2022-2501MEDIUMAn improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2EPSS 1.0%CVE-2021-39872MEDIUMIn all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still accEPSS 1.0%CVE-2020-13305LOWA vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not invalidating project invitation link upoEPSS 1.0%CVE-2020-13318MEDIUMA vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a crEPSS 1.0%CVE-2022-0740LOWIncorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 beEPSS 1.0%CVE-2024-8640HIGHImproper Neutralization of Special Elements used in a Command ('Command Injection') in GitLabEPSS 1.0%CVE-2021-39866MEDIUMA business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.EPSS 1.0%CVE-2022-3613MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versioEPSS 1.0%CVE-2021-22261HIGHA stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions stEPSS 1.0%CVE-2021-39885HIGHA Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 bEPSS 1.0%CVE-2020-13313MEDIUMA vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgrEPSS 1.0%CVE-2021-39905MEDIUMAn information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groupsEPSS 1.0%CVE-2021-22249MEDIUMA verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a groupEPSS 1.0%CVE-2022-0124MEDIUMAn issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's SEPSS 1.0%CVE-2019-15581An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project ownEPSS 1.0%CVE-2021-22230MEDIUMImproper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE EPSS 1.0%CVE-2023-3994HIGHInefficient Regular Expression Complexity in GitLabEPSS 1.0%CVE-2021-39870MEDIUMIn all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by aEPSS 1.0%CVE-2023-0485MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9EPSS 1.0%CVE-2020-13291HIGHIn GitLab before 13.2.3, project sharing could temporarily allow too permissive access.EPSS 1.0%