Exposição de GitLab

Development, Issue trackers
318
score de exposição
658
sites usam
4
em exploração
24
críticos
Análise Vexday

Com 1.068 CVEs catalogadas e 78 novas vulnerabilidades registradas nos últimos 90 dias, o GitLab apresenta um volume de exposição que exige monitoramento contínuo. A taxa de exploração ativa — 4 entradas no catálogo KEV da CISA, representando 0,37% do total — está abaixo da média geral do catálogo (0,45%), embora esse dado não elimine a atenção necessária às falhas confirmadas. A vulnerabilidade CVE-2021-22205 concentra o maior risco imediato, com score EPSS de 0,9973, indicando altíssima probabilidade de exploração ativa, e deve ser tratada como prioridade absoluta em qualquer plano de remediação. O tipo de falha mais recorrente, CWE-770 (alocação de recursos sem limite ou controle), combinado com 24 vulnerabilidades de severidade crítica, sugere atenção estrutural às práticas de desenvolvimento e à gestão de recursos na plataforma.

CVEs

1.087 resultados
CVE-2021-22178MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the PrometheuEPSS 1.1%CVE-2020-13290HIGHIn GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications pageEPSS 1.1%CVE-2022-0151MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting from 14.5.0 before 14EPSS 1.1%CVE-2023-1708MEDIUMAn issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 whEPSS 1.1%CVE-2019-15590An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where privEPSS 1.1%CVE-2020-13323HIGHA vulnerability was discovered in GitLab versions prior 13.1. Under certain conditions private merge requests could be read via TodosEPSS 1.1%CVE-2022-2592MEDIUMA lack of length validation in Snippet descriptions in GitLab CE/EE affecting all versions prior to 15.1.6, 15.2 prior to 15.2.4 and 15.3 prEPSS 1.1%CVE-2021-39903MEDIUMIn all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a EPSS 1.1%CVE-2020-13284MEDIUMA vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job TokenEPSS 1.1%CVE-2021-22263MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.EPSS 1.1%CVE-2023-5207HIGHExecution with Unnecessary Privileges in GitLabEPSS 1.1%CVE-2021-22229MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access EPSS 1.1%CVE-2020-13264MEDIUMKubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster EPSS 1.1%CVE-2019-5474An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridEPSS 1.1%CVE-2021-22198MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident meEPSS 1.1%CVE-2022-0344LOWAn issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting from 10.1 before 14.6.EPSS 1.1%CVE-2020-13268MEDIUMA specially crafted request could be used to confirm the existence of files hosted on object storage services, without disclosing their contEPSS 1.1%CVE-2021-39890LOWIt was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.EPSS 1.1%CVE-2022-1121MEDIUMA lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior tEPSS 1.1%CVE-2021-22181HIGHA denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relatiEPSS 1.1%