CVE-2021-22205criticalunder attackransomwareCWE-94

CVE-2021-22205: critical vulnerability in GitLab

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 10epss 100%
from disclosure to weapon43 days
Published on NVDApr 23
1st PoC+43d
metasploitApr 14
CISA KEV+194d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
54 public exploit(s)
Action required by CISAfederal deadline: 2021-11-17

Apply updates per vendor instructions.

In short

GitLab failed to properly validate image files uploaded to the system, allowing attackers to execute arbitrary commands remotely on the server. This is critical because it gives attackers complete control over the affected GitLab instance.

Technical detail

A file parser in GitLab CE/EE (versions 11.9+) insufficiently validates image file inputs before processing, enabling unauthenticated remote code execution via crafted image uploads. The vulnerability stems from improper input sanitization in the image handling pipeline, allowing injection of executable code that runs with GitLab process privileges.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
GitLab · GitLab
public PoCs found — 54
exploitdbwww.exploit-db.com/exploits/50532unverifiedgithubgithub.com/Al1ex/CVE-2021-22205★ 287githubgithub.com/inspiringz/CVE-2021-22205★ 238githubgithub.com/mr-r3bot/Gitlab-CVE-2021-22205★ 181githubgithub.com/XTeam-Wing/CVE-2021-22205★ 86githubgithub.com/r0eXpeR/CVE-2021-22205★ 69githubgithub.com/whwlsfb/CVE-2021-22205★ 23githubgithub.com/c0okB/CVE-2021-22205★ 13githubgithub.com/keven1z/CVE-2021-22205★ 12githubgithub.com/ZZ-SOCMAP/CVE-2021-22205★ 7githubgithub.com/faisalfs10x/GitLab-CVE-2021-22205-scanner★ 6githubgithub.com/runsel/GitLab-CVE-2021-22205-★ 3githubgithub.com/pizza-power/Golang-CVE-2021-22205-POC★ 3githubgithub.com/shang159/CVE-2021-22205-getshell★ 3githubgithub.com/findneo/GitLab-preauth-RCE_CVE-2021-22205★ 2githubgithub.com/DIVD-NL/GitLab-cve-2021-22205-nse★ 1githubgithub.com/momika233/cve-2021-22205-GitLab-13.10.2---Remote-Code-Execution-RCE-Unauthenticated-★ 1githubgithub.com/w0x68y/Gitlab-CVE-2021-22205★ 1githubgithub.com/NukingDragons/gitlab-cve-2021-22205★ 1githubgithub.com/sei-fish/CVE-2021-22205★ 0githubgithub.com/overgrowncarrot1/DejaVu-CVE-2021-22205★ 0githubgithub.com/ccordeiro/CVE-2021-22205★ 0githubgithub.com/hhhotdrink/CVE-2021-22205★ 0githubgithub.com/devdanqtuan/CVE-2021-22205★ 0githubgithub.com/hh-hunter/cve-2021-22205★ 0githubgithub.com/osungjinwoo/CVE-2021-22205-gitlab★ 0githubgithub.com/K3ysTr0K3R/CVE-2021-22205★ 0githubgithub.com/Hikikan/CVE-2021-22205★ 0githubgithub.com/cc3305/CVE-2021-22205★ 0vulncheckvulncheck.com/xdb/214fae59f95aunverifiedvulncheckvulncheck.com/xdb/779a26749ee1unverifiedvulncheckvulncheck.com/xdb/c38dd496f070unverifiedvulncheckvulncheck.com/xdb/a225f95f8778unverifiedvulncheckvulncheck.com/xdb/8e28f16d2f29unverifiedvulncheckvulncheck.com/xdb/4c0b2d5b4974unverifiedvulncheckvulncheck.com/xdb/7be0e6a85009unverifiedvulncheckvulncheck.com/xdb/75d6cfb95543unverifiedvulncheckvulncheck.com/xdb/974b5e726af6unverifiedvulncheckvulncheck.com/xdb/26d18020bcb3unverifiedcve_referencepacketstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.htmlunverifiedcve_referencepacketstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/a7a4a4af582eunverifiedvulncheckvulncheck.com/xdb/82ceb748c97funverifiedvulncheckvulncheck.com/xdb/2c9ecaf997fdunverifiedvulncheckvulncheck.com/xdb/32af9a461e47unverifiedvulncheckvulncheck.com/xdb/6de3fd36464cunverifiedvulncheckvulncheck.com/xdb/f8b573dcb225unverifiedvulncheckvulncheck.com/xdb/9338bb09fe25unverifiedvulncheckvulncheck.com/xdb/1df329ab1571unverifiedvulncheckvulncheck.com/xdb/fee8067e489bunverifiedvulncheckvulncheck.com/xdb/67ac8dff2a01unverifiedvulncheckvulncheck.com/xdb/4f08d429923eunverifiedvulncheckvulncheck.com/xdb/c4cbe11e130cunverifiedvulncheckvulncheck.com/xdb/8f0f2fc2bf7aunverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.