Vulnerability Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 11.9.0, < 13.8.8 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifToExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-ExecutionExploitThird Party AdvisoryVDB Entry
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22205.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/327121Broken Link
- https://hackerone.com/reports/1154542Permissions RequiredThird Party Advisory
- http://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifToExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-ExecutionExploitThird Party AdvisoryVDB Entry
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22205.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/327121Broken Link
- https://hackerone.com/reports/1154542Permissions RequiredThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-US Government Resource
FAQ
What is CVE-2021-22205?
CVE-2021-22205 is a vulnerability with a CVSS score of 10.0 (CRITICAL). An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote comm...
How severe is CVE-2021-22205?
CVE-2021-22205 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-22205?
Check the references section above for vendor advisories and patch information. Affected products include: Gitlab Gitlab.