CVE-2021-22205: critical vulnerability in GitLab
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply updates per vendor instructions.
GitLab failed to properly validate image files uploaded to the system, allowing attackers to execute arbitrary commands remotely on the server. This is critical because it gives attackers complete control over the affected GitLab instance.
A file parser in GitLab CE/EE (versions 11.9+) insufficiently validates image file inputs before processing, enabling unauthenticated remote code execution via crafted image uploads. The vulnerability stems from improper input sanitization in the image handling pipeline, allowing injection of executable code that runs with GitLab process privileges.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.