Vulnerabilidades em GitLab

1.129 resultados
Análise Vexday

Com 1.068 CVEs catalogadas e 78 novas surgidas nos últimos 90 dias, o GitLab apresenta um volume de vulnerabilidades que exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com 4 CVEs confirmadas em uso por agentes de ameaça, mas a presença de 83 vulnerabilidades com prova de conceito pública e 24 de severidade crítica amplia consideravelmente a superfície de risco. O destaque mais preocupante é CVE-2021-22205, atualmente a CVE mais perigosa em exploração ativa, com EPSS de 0,9973 — valor que indica probabilidade altíssima de exploração —, e cuja falha de tipo mais recorrente na plataforma, CWE-770 (alocação de recursos sem limites adequados), sugere atenção redobrada a controles de validação de entrada e gestão de recursos. Equipes de segurança devem priorizar a remediação das CVEs com PoC disponível e manter rastreamento próximo das novas emissões, dado o ritmo relevante de descobertas recentes.

CVE-2019-15585Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitEPSS 1.6%CVE-2020-13304LOWA vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated EPSS 1.6%CVE-2023-2232MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 15.10 before 16.1, leading to a ReDoS vulnerability in the Jira EPSS 1.6%CVE-2020-13296MEDIUMAn issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for DEPSS 1.6%CVE-2021-22167MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attackerEPSS 1.6%CVE-2019-5470An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could resulEPSS 1.6%CVE-2020-13271MEDIUMA Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EEEPSS 1.5%CVE-2020-13334MEDIUMIn GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the coEPSS 1.5%CVE-2020-26414MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that EPSS 1.5%CVE-2020-13343HIGHAn issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project TemplateEPSS 1.5%CVE-2022-1174MEDIUMA potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, allEPSS 1.5%CVE-2020-13311MEDIUMA vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits aEPSS 1.5%CVE-2022-0489LOWAn issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math EPSS 1.5%CVE-2021-39912MEDIUMA potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to triggEPSS 1.5%CVE-2021-39907MEDIUMA potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resuEPSS 1.5%CVE-2022-0741MEDIUMImproper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal environment variables vEPSS 1.5%CVE-2021-39940MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 beforeEPSS 1.5%CVE-2022-1431MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9EPSS 1.5%CVE-2020-26405HIGHPath traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitEPSS 1.5%CVE-2021-39942MEDIUMA denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 bEPSS 1.4%