Exposição de GitLab

Development, Issue trackers
318
score de exposição
658
sites usam
4
em exploração
24
críticos
Análise Vexday

Com 1.068 CVEs catalogadas e 78 novas vulnerabilidades registradas nos últimos 90 dias, o GitLab apresenta um volume de exposição que exige monitoramento contínuo. A taxa de exploração ativa — 4 entradas no catálogo KEV da CISA, representando 0,37% do total — está abaixo da média geral do catálogo (0,45%), embora esse dado não elimine a atenção necessária às falhas confirmadas. A vulnerabilidade CVE-2021-22205 concentra o maior risco imediato, com score EPSS de 0,9973, indicando altíssima probabilidade de exploração ativa, e deve ser tratada como prioridade absoluta em qualquer plano de remediação. O tipo de falha mais recorrente, CWE-770 (alocação de recursos sem limite ou controle), combinado com 24 vulnerabilidades de severidade crítica, sugere atenção estrutural às práticas de desenvolvimento e à gestão de recursos na plataforma.

CVEs

1.087 resultados
CVE-2022-3613MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versioEPSS 1.0%CVE-2021-22249MEDIUMA verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a groupEPSS 1.0%CVE-2022-0124MEDIUMAn issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's SEPSS 1.0%CVE-2022-1417MEDIUMImproper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9EPSS 1.0%CVE-2022-3279LOWAn unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15EPSS 1.0%CVE-2022-0740LOWIncorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 beEPSS 1.0%CVE-2022-1783LOWAn issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 beforEPSS 1.0%CVE-2019-15581An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project ownEPSS 1.0%CVE-2021-22230MEDIUMImproper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE EPSS 1.0%CVE-2023-3994HIGHInefficient Regular Expression Complexity in GitLabEPSS 1.0%CVE-2023-0485MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9EPSS 1.0%CVE-2021-39870MEDIUMIn all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by aEPSS 1.0%CVE-2020-13291HIGHIn GitLab before 13.2.3, project sharing could temporarily allow too permissive access.EPSS 1.0%CVE-2021-39910LOWAn issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 beforeEPSS 1.0%CVE-2021-22223MEDIUMClient-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT EPSS 0.9%CVE-2022-0125MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.EPSS 0.9%CVE-2021-22227MEDIUMA reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious liEPSS 0.9%CVE-2021-22179MEDIUMA vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature.EPSS 0.9%CVE-2024-2818MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.9%CVE-2021-39905MEDIUMAn information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groupsEPSS 0.9%