Executive brief
GitLab Community and Enterprise Editions fail to properly validate image files passed to an internal file parser (ExifTool) via GitLab Workhorse. This flaw allows an unauthenticated remote attacker to execute arbitrary commands on the server by uploading a specially crafted image file.
Affected products
- GitLab GitLab Community Edition >=11.9, <13.8.8; >=13.9, <13.9.6; >=13.10, <13.10.3
- GitLab GitLab Enterprise Edition >=11.9, <13.8.8; >=13.9, <13.9.6; >=13.10, <13.10.3
Timeline
- 2021-04-30: disclosed: Initial NVD analysis and disclosure
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: other: Vulnerability reported as exploited in the wild