#VU52499 OS Command Injection in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2021-22205
Published: April 22, 2021 / Updated: May 23, 2024
Gitlab Community Edition
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation within image parser when processing image files. A remote authenticated user can upload a specially crafted image file to the system and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.