CVE-2021-22205 - GitLab Community and Enterprise Editions Remote Code Execution Vulnerability
Project:GitLab
Product:Community and Enterprise Editions
Date Added:2021-11-03Due Date:2021-11-17
Vulnerability Name
GitLab Community and Enterprise Editions Remote Code Execution Vulnerability
Description
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.
Known To Be Used in Ransomware Campaigns?
Known
Action
Apply updates per vendor instructions.
Additional Notes
https://nvd.nist.gov/vuln/detail/CVE-2021-22205
Related News Articles
China-Linked Hackers Exploit SAP and SQL Server Flaws in Attacks Across Asia and BrazilMay 30, 2025