CVE-2021-22205: GitLab Community and Enterprise Editions Remote Code Execution Vulnerability
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.
Other sources
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22205?
CVE-2021-22205 is classified as critical due to its potential for remote code execution.
How do I fix CVE-2021-22205?
To remediate CVE-2021-22205, upgrade GitLab Community and Enterprise Editions to versions 13.10.3, 13.9.6, or 13.8.8 or later.
What versions of GitLab are affected by CVE-2021-22205?
CVE-2021-22205 affects GitLab versions ranging from 11.9.0 to 13.8.8 and some versions between 13.9.0 to 13.9.6 and 13.10.0 to 13.10.3.
What type of vulnerability is CVE-2021-22205?
CVE-2021-22205 is a remote code execution vulnerability due to improper validation of image file extensions.
Who is affected by CVE-2021-22205?
Organizations using GitLab Community and Enterprise Editions with the image upload feature enabled are vulnerable to CVE-2021-22205.