Junglewise Threat Intelligence

CVE-2021-22205: GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

CVE-2021-22205 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2021-11-03

Technologies: GitLab Community Edition, GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab Community and Enterprise Editions fail to properly validate image files passed to an internal file parser (ExifTool) via GitLab Workhorse. This flaw allows an unauthenticated remote attacker to execute arbitrary commands on the server by uploading a specially crafted image file.

Affected products

  • GitLab GitLab Community Edition >=11.9, <13.8.8; >=13.9, <13.9.6; >=13.10, <13.10.3
  • GitLab GitLab Enterprise Edition >=11.9, <13.8.8; >=13.9, <13.9.6; >=13.10, <13.10.3

Timeline

  • 2021-04-30: disclosed: Initial NVD analysis and disclosure
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: other: Vulnerability reported as exploited in the wild

Related threats