HackerFeeds
All CVEs

CVE-2021-22205

CRITICAL10.0
CISA KEV

Published 2021-04-23 · Updated 2026-08-06 · Source cve@gitlab.com

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CWE-94CWE-94

CISA Known-Exploited Vulnerability

Product: GitLabCommunity and Enterprise Editions

Name: GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

Date added: 2021-11-03 · Due: 2021-11-17

USED IN RANSOMWARE

Required action: Apply updates per vendor instructions.

View on NVD