CVE-2021-22205

NVD Published Date: April 23, 2021 at 06:15 PM
NVD Last Modified: July 12, 2022 at 05:42 PM
Download Patch
Vulnerability ID
CVE-2021-22205
Severity
CRITICAL
Severity Score
10.0
Summary
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
Mitigation and Patches
-
Exploits

https://www.exploit-db.com/exploits/50532

https://github.com/Al1ex/CVE-2021-22205

https://github.com/inspiringz/CVE-2021-22205

https://github.com/mr-r3bot/Gitlab-CVE-2021-22205

https://github.com/XTeam-Wing/CVE-2021-22205

https://github.com/r0eXpeR/CVE-2021-22205

https://github.com/Seals6/CVE-2021-22205

https://github.com/whwlsfb/CVE-2021-22205

https://github.com/c0okB/CVE-2021-22205

https://github.com/keven1z/CVE-2021-22205

https://github.com/ZZ-SOCMAP/CVE-2021-22205

https://github.com/faisalfs10x/GitLab-CVE-2021-22205-scanner

https://github.com/findneo/GitLab-preauth-RCE_CVE-2021-22205

https://github.com/runsel/GitLab-CVE-2021-22205-

https://github.com/pizza-power/Golang-CVE-2021-22205-POC

https://github.com/shang159/CVE-2021-22205-getshell

https://github.com/mr-r3bot/Gitlab-CVE-2021-22205

https://github.com/RedTeamWing/CVE-2021-22205

https://github.com/r0eXpeR/CVE-2021-22205

https://github.com/Al1ex/CVE-2021-22205

https://github.com/whwlsfb/CVE-2021-22205

https://github.com/c0okB/CVE-2021-22205

https://github.com/Seals6/CVE-2021-22205

https://github.com/shang159/CVE-2021-22205-getshell

https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/gitlab_exif_rce.rb

https://security.humanativaspa.it/gitlab-ce-cve-2021-22205-in-the-wild/

https://www.cisa.gov/known-exploited-vulnerabilities-catalog

https://github.com/inspiringz/CVE-2021-22205

https://github.com/faisalfs10x/GitLab-CVE-2021-22205-scanner

https://github.com/XTeam-Wing/CVE-2021-22205

http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.html

http://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.html

https://github.com/antx-code/CVE-2021-22205

https://github.com/findneo/GitLab-preauth-RCE_CVE-2021-22205

https://github.com/keven1z/CVE-2021-22205

https://github.com/pizza-power/Golang-CVE-2021-22205-POC

https://github.com/runsel/GitLab-CVE-2021-22205-

https://github.com/ZZ-SOCMAP/CVE-2021-22205

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE ID
CWE-94

Recent Publish

CVE-2021-35211

KB5046613

KB5046615

CVE-2021-44228

CVE-2022-22536

KB5046616

See More ...

See SecOps Solution
in action

Schedule Demo