CVE-2021-22205
CRITICAL KEV CISA Exploitation: ACTIVE
Ransomware noto
10.0
CVSS 3.1
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
Metadata
Severity & Metrics
10.0
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
CISA Known Exploited Vulnerability
Required action
Apply updates per vendor instructions.
CISA description
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| GitLab | GitLab | — | >=11.9, <13.8.8, >=13.9, <13.9.6, >=13.10, <13.10.3 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | Improper control of generation of code ('code injection') in GitLab |
| CWE-94 | adp | CWE-94 Improper Control of Generation of Code ('Code Injection') |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 10.0 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
References (5)
- https://hackerone.com/reports/1154542
- https://gitlab.com/gitlab-org/gitlab/-/issues/327121
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22205.json
- http://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.html
- http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.html