CVE-2021-22205
KEV · ransomware Critical · CVSS 10.0- CVSS
- 10.0
- nvd
- EPSS
- —
- KEV
- Listed
- ransomware
- Class
- oss containerizable
- CWE-94, CWE-94
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
Affected packages
| Bitnami | gitlab | 11.9.0 → 13.8.8 |
| Bitnami | gitlab | 13.10.0 → 13.10.3 |
| Bitnami | gitlab | 13.9.0 → 13.9.6 |
References
- http://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.html
- http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.html
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22205.json
- https://gitlab.com/gitlab-org/gitlab/-/issues/327121
- https://hackerone.com/reports/1154542
- http://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.html
- http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.html
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22205.json
- https://gitlab.com/gitlab-org/gitlab/-/issues/327121
- https://hackerone.com/reports/1154542
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22205
Status: profiled · ingested 2026-08-01T06:00:04.000Z