ZeroHour

CVE-2021-22205

KEV ransomware PoC ×2large

Unauthenticated RCE in GitLab CE/EE via ExifTool Image Parsing (CVE-2021-22205)

CISA: GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

CVSS 3.1
10.0 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

GitLab CE/EE versions from 11.9 onward fail to properly validate image files before passing them to the bundled ExifTool file parser, enabling command/code injection (CWE-94). A remote, unauthenticated attacker triggers it by getting the server to parse a specially crafted image (e.g., through file-upload features), with no credentials or user interaction required. Successful exploitation yields arbitrary command execution on the GitLab server, exposing source code, credentials, CI/CD data, and the wider network (CVSS 10.0, scope-changed). All self-managed GitLab Community and Enterprise Edition deployments on affected versions are exposed. The flaw is actively exploited in the wild: it is on CISA's KEV with known ransomware use, public PoCs exist, and 2021 campaigns used it for ransomware, cryptojacking, and access brokering against GitLab servers.

What to do: Upgrade immediately to the patched releases - 13.10.3 or later, or the corresponding 13.9.6/13.8.6/13.7.9 backports - per vendor instructions, as required for KEV entries. Until patched, restrict network access to internet-facing GitLab instances and verify the bundled ExifTool is current. Hunt for signs of compromise (suspicious processes or cron jobs, cryptominers, webshells, new SSH keys, unexpected outbound connections), given documented ransomware and cryptojacking abuse.

Affected
GitLab Community Edition (CE) and Enterprise Edition (EE), self-managedAll versions starting from 11.9 through versions prior to the vendor's April 2021 patch releases (fixed in 13.10.3, 13.9.6, 13.8.6, and 13.7.9)
Estimated exposure
largetens of thousands of internet-exposed self-managed GitLab instances (order of ~50,000+ servers in public scans) — Public internet scans around the disclosure period counted tens of thousands of exposed self-managed GitLab CE/EE servers, and GitLab's large self-hosted install base makes this far above 10k affected systems while remaining below mass…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

CISA Known Exploited Vulnerability
Affected
GitLab Community and Enterprise Editions
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
gitlab
Products
gitlab
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news