Skip to content
COOEY

EXPOSURES › CVE-2021-22205

CVE-2021-22205

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-22205 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

GitLab's image upload functionality allowed remote code execution due to improper validation of image files by ExifTool, actively exploited in ransomware attacks.

A critical vulnerability in GitLab allowed attackers to execute arbitrary code via image uploads, leveraging ExifTool's flawed validation. DIB organizations using GitLab should immediately patch to prevent potential data breaches and ransomware infections. This failure highlights the risk of relying on third-party libraries without proper security review and validation.

Shame score — The vulnerability's exploitation in ransomware attacks and the reliance on a known, easily-exploitable flaw in ExifTool demonstrate significant negligence.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
cooey ↗ severe-fallout -0.70
negative
"GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.