Vulnerabilidades em GitLab

1.129 resultados
Análise Vexday

Com 1.068 CVEs catalogadas e 78 novas surgidas nos últimos 90 dias, o GitLab apresenta um volume de vulnerabilidades que exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com 4 CVEs confirmadas em uso por agentes de ameaça, mas a presença de 83 vulnerabilidades com prova de conceito pública e 24 de severidade crítica amplia consideravelmente a superfície de risco. O destaque mais preocupante é CVE-2021-22205, atualmente a CVE mais perigosa em exploração ativa, com EPSS de 0,9973 — valor que indica probabilidade altíssima de exploração —, e cuja falha de tipo mais recorrente na plataforma, CWE-770 (alocação de recursos sem limites adequados), sugere atenção redobrada a controles de validação de entrada e gestão de recursos. Equipes de segurança devem priorizar a remediação das CVEs com PoC disponível e manter rastreamento próximo das novas emissões, dado o ritmo relevante de descobertas recentes.

CVE-2020-13341MEDIUMAn issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Insufficient permission check allows attaEPSS 1.2%CVE-2021-39941LOWAn information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project membEPSS 1.2%CVE-2022-1460MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4EPSS 1.2%CVE-2022-1148MEDIUMImproper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, anEPSS 1.2%CVE-2022-2251MEDIUMImproper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.EPSS 1.2%CVE-2022-2497HIGHAn issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.0.5, all versions starting from 15.1 beforeEPSS 1.2%CVE-2021-39875MEDIUMIn all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visitEPSS 1.2%CVE-2020-13295MEDIUMFor GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.EPSS 1.2%CVE-2020-26417MEDIUMInformation disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6EPSS 1.2%CVE-2020-13303HIGHA vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthoEPSS 1.2%CVE-2023-4522MEDIUMImproper Validation of Specified Type of Input in GitLabEPSS 1.2%CVE-2020-13322HIGHA vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthorized user can create aEPSS 1.1%CVE-2021-22210MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GEPSS 1.1%CVE-2020-13274HIGHA security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLEPSS 1.1%CVE-2020-13301MEDIUMA vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a stored XSS on the standaloneEPSS 1.1%CVE-2022-0152MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14EPSS 1.1%CVE-2022-1406MEDIUMImproper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14EPSS 1.1%CVE-2021-22195HIGHClient side code execution in gitlab-vscode-extension v3.15.0 and earlier allows attacker to execute code on user systemEPSS 1.1%CVE-2022-0249LOWA vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared addEPSS 1.1%CVE-2021-39903MEDIUMIn all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a EPSS 1.1%