vulnti.work

GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

Critical Listed in CISA KEV
CVECVE-2021-22205
First seen2021-11-03 00:00 UTC
Disclosed2021-11-03 00:00 UTC
Last updated2026-07-18 07:15 UTC
Channel statuspending_review

Summary

GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • GitLab:Community and Enterprise Editions

Sources

  • CISA KEV DATABASE

Original Links

Timeline

  1. kev_added CISA KEV
  2. kev_ingest CISA KEV