Vulnerabilidades em GitLab

1.129 resultados
Análise Vexday

Com 1.068 CVEs catalogadas e 78 novas surgidas nos últimos 90 dias, o GitLab apresenta um volume de vulnerabilidades que exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com 4 CVEs confirmadas em uso por agentes de ameaça, mas a presença de 83 vulnerabilidades com prova de conceito pública e 24 de severidade crítica amplia consideravelmente a superfície de risco. O destaque mais preocupante é CVE-2021-22205, atualmente a CVE mais perigosa em exploração ativa, com EPSS de 0,9973 — valor que indica probabilidade altíssima de exploração —, e cuja falha de tipo mais recorrente na plataforma, CWE-770 (alocação de recursos sem limites adequados), sugere atenção redobrada a controles de validação de entrada e gestão de recursos. Equipes de segurança devem priorizar a remediação das CVEs com PoC disponível e manter rastreamento próximo das novas emissões, dado o ritmo relevante de descobertas recentes.

CVE-2022-2270LOWAn issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0EPSS 0.9%CVE-2022-1433LOWAn issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.EPSS 0.9%CVE-2021-39904MEDIUMAn Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions sEPSS 0.8%CVE-2022-3514MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starting from 15.6 before EPSS 0.8%CVE-2023-3205MEDIUMInefficient Regular Expression Complexity in GitLabEPSS 0.8%CVE-2022-2428MEDIUMA crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allowsEPSS 0.8%CVE-2020-13283HIGHFor GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issues list via milestone title.EPSS 0.8%CVE-2021-22197LOWAn issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 where an infinite loop exist when an authenticated usEPSS 0.8%CVE-2021-22237MEDIUMUnder specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. EPSS 0.8%CVE-2025-13927HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.8%CVE-2022-4131MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 15.5.7, all versions starting from 15.6 beforeEPSS 0.8%CVE-2021-22183MEDIUMAn issue has been discovered in GitLab affecting all versions starting with 11.8. GitLab was vulnerable to a stored XSS in the epics page, wEPSS 0.8%CVE-2021-39947MEDIUMIn specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2 would re-use the fiEPSS 0.8%CVE-2021-22247MEDIUMImproper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analyticsEPSS 0.8%CVE-2021-39889MEDIUMIn all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protecEPSS 0.8%CVE-2022-3726MEDIUMLack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prEPSS 0.8%CVE-2021-22169MEDIUMAn issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages.EPSS 0.8%CVE-2021-22250MEDIUMImproper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administEPSS 0.8%CVE-2023-5356HIGHIncorrect Authorization in GitLabEPSS 0.8%CVE-2023-0805MEDIUMAn issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6, all versions starting from 15.10 before 1EPSS 0.8%