Vulnerabilities in GitLab

1,068 results
Vexday analysis

Com 1.068 CVEs catalogadas e 78 novas surgidas nos últimos 90 dias, o GitLab apresenta um volume de vulnerabilidades que exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com 4 CVEs confirmadas em uso por agentes de ameaça, mas a presença de 83 vulnerabilidades com prova de conceito pública e 24 de severidade crítica amplia consideravelmente a superfície de risco. O destaque mais preocupante é CVE-2021-22205, atualmente a CVE mais perigosa em exploração ativa, com EPSS de 0,9973 — valor que indica probabilidade altíssima de exploração —, e cuja falha de tipo mais recorrente na plataforma, CWE-770 (alocação de recursos sem limites adequados), sugere atenção redobrada a controles de validação de entrada e gestão de recursos. Equipes de segurança devem priorizar a remediação das CVEs com PoC disponível e manter rastreamento próximo das novas emissões, dado o ritmo relevante de descobertas recentes.

CVE-2024-0199HIGHIncorrect Authorization in GitLabEPSS 0.7%CVE-2020-13327MEDIUMAn issue has been discovered in GitLab Runner affecting all versions starting from 13.4.0 before 13.4.2, all versions starting from 13.3.0 bEPSS 0.7%CVE-2022-3067MEDIUMAn issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versioEPSS 0.7%CVE-2021-22262MEDIUMMissing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versEPSS 0.7%CVE-2023-3205MEDIUMInefficient Regular Expression Complexity in GitLabEPSS 0.7%CVE-2022-3870MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 beforeEPSS 0.7%CVE-2020-13338MEDIUMAn issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability wasEPSS 0.7%CVE-2020-13326MEDIUMA vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the restriction for Github project import could beEPSS 0.7%CVE-2022-1189LOWAn issue has been discovered in GitLab CE/EE affecting all versions starting from 12.2 before 14.7.7, all versions starting from 14.8 beforeEPSS 0.7%CVE-2024-6324MEDIUMInefficient Algorithmic Complexity in GitLabEPSS 0.7%CVE-2020-13350LOWCSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators toEPSS 0.7%CVE-2022-4289MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 15.3 before 15.7.8, versions of 15.8 before 15.8.4, and version EPSS 0.7%CVE-2023-2013LOWAn issue has been discovered in GitLab CE/EE affecting all versions starting from 1.2 before 15.10.8, all versions starting from 15.11 beforEPSS 0.7%CVE-2020-13289MEDIUMA vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted EPSS 0.7%CVE-2022-1124MEDIUMAn improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior tEPSS 0.7%CVE-2022-2498MEDIUMAn issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15EPSS 0.7%CVE-2024-8114HIGHMissing Authorization in GitLabEPSS 0.7%CVE-2023-5933MEDIUMImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLabEPSS 0.7%CVE-2023-0450LOWAn issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and from 15.10 to 15.10.EPSS 0.7%CVE-2020-13282LOWFor GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroupEPSS 0.7%