CRITICAL
CVE-2021-22205
CVSS
10
KEV
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
Summary dbcve.org
GitLab CE/EE versions 11.9 and later fail to properly validate image files processed by a file parser, allowing attackers to inject and execute arbitrary commands on the affected server through specially crafted image files.
Mitigation
Upgrade GitLab to the patched version (13.10.3, 13.9.6, or 13.8.8 depending on version) or later. If immediate patching is not possible, restrict file upload capabilities and implement network-level controls to limit exposure.
Weakness (CWE)
CWE-94
Code Injection
EPSS Score
99.73%
Probability of exploitation in next 30 days
100th percentile
References
http://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.html
Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.html
Exploit, Third Party Advisory, VDB Entry
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22205.json
Vendor Advisory
https://gitlab.com/gitlab-org/gitlab/-/issues/327121
Broken Link
https://hackerone.com/reports/1154542
Permissions Required, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22205
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.