OS Command Injection in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2021-22205

 

OS Command Injection in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2021-22205

Published: April 22, 2021 / Updated: May 23, 2024


Vulnerability identifier: #VU52499
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22205
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation within image parser when processing image files. A remote authenticated user can upload a specially crafted image file to the system and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

GitLab Enterprise Edition
Gitlab Community Edition
Arch Linux

How to mitigate CVE-2021-22205

Install updates from vendor's website.

GitLab Enterprise Edition - addressed in versions 13.8.8, 13.9.6, 13.10.3
Gitlab Community Edition - addressed in versions 13.8.8, 13.9.6, 13.10.3

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins