CVE-2021-22205
critical
KEV
CVSS v3
—
CVSS v2
—
VIR risk
10.0
Description
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.
CISA KEV
- Vendor
- GitLab
- Product
- Community and Enterprise Editions
- Due date
- 2021-11-17
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://nvd.nist.gov/vuln/detail/CVE-2021-22205
Vendor advisory: arch — https://security.archlinux.org/ASA-202104-1
Exploits
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 13.10.3-1 |
References
Verify integrity in audit chain (admin only). AS-IS.