Vulnerabilidades em GitLab

1.087 resultados
Análise Vexday

Com 1.068 CVEs catalogadas e 78 novas surgidas nos últimos 90 dias, o GitLab apresenta um volume de vulnerabilidades que exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com 4 CVEs confirmadas em uso por agentes de ameaça, mas a presença de 83 vulnerabilidades com prova de conceito pública e 24 de severidade crítica amplia consideravelmente a superfície de risco. O destaque mais preocupante é CVE-2021-22205, atualmente a CVE mais perigosa em exploração ativa, com EPSS de 0,9973 — valor que indica probabilidade altíssima de exploração —, e cuja falha de tipo mais recorrente na plataforma, CWE-770 (alocação de recursos sem limites adequados), sugere atenção redobrada a controles de validação de entrada e gestão de recursos. Equipes de segurança devem priorizar a remediação das CVEs com PoC disponível e manter rastreamento próximo das novas emissões, dado o ritmo relevante de descobertas recentes.

CVE-2021-22175MEDIUMWhen requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versionsEPSS 53.4%KEVCVE-2024-1451HIGHImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabEPSS 51.5%CVE-2023-3364HIGHInefficient Regular Expression Complexity in GitLabEPSS 44.5%CVE-2024-8124HIGHInefficient Regular Expression Complexity in GitLabEPSS 40.0%CVE-2021-39935MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 beforeEPSS 35.6%KEVCVE-2020-26413MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL resEPSS 34.9%CVE-2024-2454MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 33.3%CVE-2024-2651MEDIUMInefficient Regular Expression Complexity in GitLabEPSS 33.3%CVE-2024-4901HIGHImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabEPSS 33.0%CVE-2021-22214MEDIUMWhen requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all veEPSS 27.8%CVE-2024-2829HIGHInefficient Regular Expression Complexity in GitLabEPSS 26.0%CVE-2024-2434HIGHImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLabEPSS 22.9%CVE-2024-2878HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 19.3%CVE-2022-1680CRITICALAn account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting fEPSS 15.5%CVE-2024-4024HIGHAuthentication Bypass by Assumed-Immutable Data in GitLabEPSS 14.9%CVE-2022-0735CRITICALAn issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 beforEPSS 13.2%CVE-2021-22192CRITICALAn issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute EPSS 13.1%CVE-2025-5121HIGHMissing Authorization in GitLabEPSS 9.5%CVE-2025-4278HIGHImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLabEPSS 8.3%CVE-2023-5009CRITICALIncorrect Authorization in GitLabEPSS 8.3%