claytonvantol.us
SESSION: secure TLS: 1.3 PID: 1337

clayton@site:~/news$ cat cve-2021-22205-gitlab-community-and-enterprise-editions.log

CVE-2021-22205 — GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

2021-11-03 • CISA Known Exploited Vulnerability


[event] GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.

> AFFECTED SOFTWARE

Field Value
Vendor GitLab
Product Community and Enterprise Editions
CWE CWE-20, CWE-95
CVE ID CVE-2021-22205
Date Added 2021-11-03
Due Date 2021-11-17
Ransomware Campaign Known — this vulnerability has been leveraged in ransomware campaigns

> MITIGATION

Apply updates per vendor instructions.

Due Date: 2021-11-17

> REFERENCES


← back to terminal

UPTIME: 1337d v2.0.1 privacy LAST LOGIN: 2026-05-30 20:36:15 UTC