NVD disclosure day

Published threat advisories for April 23, 2021

CVE advisoryKnown Exploit

CVE-2021-22205

GitLab Remote Command Execution Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

GitLab instances accepting image uploads are affected by a remote command execution vulnerability. This allows attackers to run unauthorized commands, potentially compromising systems and data, posing a significant business risk. Organizations should identify all instances and apply vendor updates.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-22893

Pulse Connect Secure Authentication Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Ivanti Pulse Connect Secure allows unauthenticated remote code execution, impacting systems and data. The exploit has been observed in the wild, posing a significant business risk. Affected organizations should identify and isolate exposed assets, apply vendor fixes, and monitor for related issues.

• CISA KEV