CVE-2021-22205
GitLab Community and Enterprise Editions: Remote Code Execution
As of , CVE-2021-22205 in GitLab Community and Enterprise Editions is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 3 November 2021
- US federal deadline
- 17 November 202114 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- KnownCISA changed it from Unknown to Known on 12 May 2025.
- EPSS score
- 0.99Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- Not availableCISA listed it before 4 February 2022, where the EPSS files we read begin.
- Public exploit
- 1 Metasploit module and 1 Exploit-DB entry
- Fix
- No vendor link in CISA's entry
What CISA says to do
Apply updates per vendor instructions.
CISA's required action
What the flaw is
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.
CISA's description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
The CVE record's description, from GitLab
- CVE published
- 23 April 2021
- Assigned by
- GitLab
- CVSS
- 10.0 Critical (CVSS 3.1, from the CNA)
- CWE-94
- Improper Control of Generation of Code ('Code Injection')
- CWE-20
- Improper Input Validation
- CWE-95
- Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- yes
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- Exploit-DB published an exploit (EDB-ID 50532).
- The US federal deadline to fix it.
- CISA changed its entry. Ransomware use: Unknown to Known.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: GitLab Unauthenticated Remote ExifTool Command Injectionexploit module, rank excellent
- Exploit-DB: GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated)EDB-ID 50532, 17 November 2021
Community and Enterprise Editions: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2021-39935Server-Side Request Forgery (SSRF) | GitLab Community and Enterprise Editions | Patch soon | 0.36 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org