Exposição de GitLab

Development, Issue trackers
318
score de exposição
658
sites usam
4
em exploração
24
críticos
Análise Vexday

Com 1.068 CVEs catalogadas e 78 novas vulnerabilidades registradas nos últimos 90 dias, o GitLab apresenta um volume de exposição que exige monitoramento contínuo. A taxa de exploração ativa — 4 entradas no catálogo KEV da CISA, representando 0,37% do total — está abaixo da média geral do catálogo (0,45%), embora esse dado não elimine a atenção necessária às falhas confirmadas. A vulnerabilidade CVE-2021-22205 concentra o maior risco imediato, com score EPSS de 0,9973, indicando altíssima probabilidade de exploração ativa, e deve ser tratada como prioridade absoluta em qualquer plano de remediação. O tipo de falha mais recorrente, CWE-770 (alocação de recursos sem limite ou controle), combinado com 24 vulnerabilidades de severidade crítica, sugere atenção estrutural às práticas de desenvolvimento e à gestão de recursos na plataforma.

CVEs

1.087 resultados
CVE-2022-1413MEDIUMMissing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and EPSS 0.9%CVE-2022-0093LOWAn issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allEPSS 0.9%CVE-2022-0477MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.EPSS 0.9%CVE-2021-39945LOWImproper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 befoEPSS 0.9%CVE-2021-39939MEDIUMAn uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions stEPSS 0.9%CVE-2022-1100MEDIUMA potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 1EPSS 0.9%CVE-2022-0549MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versioEPSS 0.9%CVE-2021-39934MEDIUMImproper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before EPSS 0.9%CVE-2023-3424HIGHInefficient Regular Expression Complexity in GitLabEPSS 0.9%CVE-2021-39873MEDIUMIn all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to trick users into visitEPSS 0.9%CVE-2017-0920GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::EPSS 0.9%CVE-2020-13349MEDIUMAn issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a file path resulted inEPSS 0.9%CVE-2022-0390MEDIUMImproper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retriEPSS 0.9%CVE-2021-39868MEDIUMIn all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited reposEPSS 0.9%CVE-2023-1178MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5,EPSS 0.9%CVE-2021-22224HIGHA cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed aEPSS 0.9%CVE-2021-39867MEDIUMIn all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to triggEPSS 0.9%CVE-2024-9164CRITICALMissing Authentication for Critical Function in GitLabEPSS 0.9%CVE-2022-2527HIGHAn issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions staEPSS 0.9%CVE-2021-39938LOWA vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, allEPSS 0.9%