GitLab Community and Enterprise Editions Remote Code Execution Vulnerability
Critical Listed in CISA KEV
Summary
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- GitLab:Community and Enterprise Editions
Sources
- CISA KEV DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2021-22205 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV