Exposição de GitLab

Development, Issue trackers
318
score de exposição
658
sites usam
4
em exploração
24
críticos
Análise Vexday

Com 1.068 CVEs catalogadas e 78 novas vulnerabilidades registradas nos últimos 90 dias, o GitLab apresenta um volume de exposição que exige monitoramento contínuo. A taxa de exploração ativa — 4 entradas no catálogo KEV da CISA, representando 0,37% do total — está abaixo da média geral do catálogo (0,45%), embora esse dado não elimine a atenção necessária às falhas confirmadas. A vulnerabilidade CVE-2021-22205 concentra o maior risco imediato, com score EPSS de 0,9973, indicando altíssima probabilidade de exploração ativa, e deve ser tratada como prioridade absoluta em qualquer plano de remediação. O tipo de falha mais recorrente, CWE-770 (alocação de recursos sem limite ou controle), combinado com 24 vulnerabilidades de severidade crítica, sugere atenção estrutural às práticas de desenvolvimento e à gestão de recursos na plataforma.

CVEs

1.087 resultados
CVE-2021-22176MEDIUMAn issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members toEPSS 1.0%CVE-2021-39897LOWImproper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent groEPSS 1.0%CVE-2021-22168MEDIUMA regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.EPSS 1.0%CVE-2021-22231LOWA denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access to their profile paEPSS 1.0%CVE-2021-22234CRITICALAn issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 befEPSS 1.0%CVE-2020-13292CRITICALIn GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.EPSS 1.0%CVE-2023-6159MEDIUMInefficient Regular Expression Complexity in GitLabEPSS 1.0%CVE-2021-22241HIGHAn issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripEPSS 1.0%CVE-2021-22193LOWAn issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to validate the use ofEPSS 1.0%CVE-2021-39872MEDIUMIn all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still accEPSS 1.0%CVE-2020-13305LOWA vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not invalidating project invitation link upoEPSS 1.0%CVE-2020-13318MEDIUMA vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a crEPSS 1.0%CVE-2024-8640HIGHImproper Neutralization of Special Elements used in a Command ('Command Injection') in GitLabEPSS 1.0%CVE-2021-39895MEDIUMIn all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project export so when an unEPSS 1.0%CVE-2022-2501MEDIUMAn improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2EPSS 1.0%CVE-2021-39866MEDIUMA business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.EPSS 1.0%CVE-2021-39885HIGHA Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 bEPSS 1.0%CVE-2021-22261HIGHA stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions stEPSS 1.0%CVE-2020-13313MEDIUMA vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgrEPSS 1.0%CVE-2022-1954MEDIUMA Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 prior to 14.10.5, 15.0 prior to 15.0.EPSS 1.0%