EXPOSURES › CVE-2021-22205
CVE-2021-22205
CRITICAL ⌖ ON CISA KEV · EXPLOITEDGitLab's image upload functionality allowed remote code execution due to improper validation of image files by ExifTool, actively exploited in ransomware attacks.
A critical vulnerability in GitLab allowed attackers to execute arbitrary code via image uploads, leveraging ExifTool's flawed validation. DIB organizations using GitLab should immediately patch to prevent potential data breaches and ransomware infections. This failure highlights the risk of relying on third-party libraries without proper security review and validation.
Shame score — The vulnerability's exploitation in ransomware attacks and the reliance on a known, easily-exploitable flaw in ExifTool demonstrate significant negligence.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.
"GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files."