GitLab Community and Enterprise Editions Remote Code Execution Vulnerability
Critical CVSS 10.0 Listed in CISA KEV
Summary
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- GitLab:Community and Enterprise Editions
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2021-22205 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- http://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.html Exploit
- http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.html Exploit
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22205.json Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/327121 Broken Link
- https://hackerone.com/reports/1154542 Permissions Required
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22205 US Government Resource
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD