CVE-2021-22205
GitLab Community and Enterprise Editions Remote Code Execution Vulnerability
CVSS
10.0
Crítico
EPSS
99.7%
p100
KEV
SÍ
3 nov 2021
Exploit Today
80
0-100
Publicado: 23 abr 2021 · Última mod.: 6 ago 2026 · CWE-94
Producto
GitLab / Community and Enterprise Editions
Vulnerabilidad
GitLab Community and Enterprise Editions Remote Code Execution Vulnerability
Añadido a KEV
3 nov 2021
Remediar antes de
17 nov 2021
Uso conocido en ransomware
Sí
Descripción resumida
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.
Acción requerida
Apply updates per vendor instructions.
Notas
https://nvd.nist.gov/vuln/detail/CVE-2021-22205
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
- packetstormsecurity.comhttp://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.html
- gitlab.comhttps://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22205.json
- gitlab.comhttps://gitlab.com/gitlab-org/gitlab/-/issues/327121
- hackerone.comhttps://hackerone.com/reports/1154542
- packetstormsecurity.comhttp://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.html
- gitlab.comhttps://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22205.json
- gitlab.comhttps://gitlab.com/gitlab-org/gitlab/-/issues/327121
- hackerone.comhttps://hackerone.com/reports/1154542
- www.cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22205