An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
CVE Infomation | Exploits or more Infomation |
---|---|
mitre | EXPLOIT DATABASE |
NVD | 0day.today |
vulmon.com | github |
CVE Details | |
JVN ENG JPN | |
Reconshell |
Software Tag:
List of frequently cited URLs
User | URL | Info Source | Date |
---|---|---|---|
deepfence | https://twitter.com/deepfence/status/1615382403798958080/ph... | Source deepfence 1615382403798958080 | 2023/01/18 |
deepfence | https://forum.gitlab.com/t/cve-2021-22205-how-to-determine-... | Source deepfence 1615382407443779584 | 2023/01/18 |
ET_Labs | https://community.emergingthreats.net/t/gitlab-pre-auth-rce... | Source ET_Labs 1626749368710602752 | 2023/02/18 |
ET_Labs | https://twitter.com/ET_Labs/status/1626749368710602752/photo/1 | Source ET_Labs 1626749368710602752 | 2023/02/18 |
ET_Labs | http://hackerone.com/reports/1154542 | Source ET_Labs 1626749382065258498 | 2023/02/18 |
ET_Labs | http://devcraft.io/2021/05/04/exiftool-arbitrary-code-execu... | Source ET_Labs 1626749382065258498 | 2023/02/18 |
List of frequently cited URLs
URL | Num of Times Referred to |
---|---|
lists.astaro.com | 24 |
censys.io | 6 |
thehackernews.com | 6 |
twitter.com | 4 |
attackerkb.com | 4 |
about.gitlab.com | 4 |
www.helpnetsecurity.com | 4 |
security.humanativaspa.it | 4 |
github.com | 3 |
www.rapid7.com | 3 |
therecord.media | 3 |
feedproxy.google.com | 3 |
ipssignatures.appspot.com | 3 |
User | URL | Info Source |
---|---|---|
deepfence | twitter.com | Show Tweet |
deepfence | forum.gitlab.com | Show Tweet |
ET_Labs | community.emergingthreats.net | Show Tweet |
ET_Labs | twitter.com | Show Tweet |
ET_Labs | hackerone.com | Show Tweet |
ET_Labs | devcraft.io | Show Tweet |
Name | URL |
---|---|
mr-r3bot/Gitlab-CVE-2021-22205 | https://github.com/mr-r3bot/Gitlab-CVE-2021-22205 |
Al1ex/CVE-2021-22205 | https://github.com/Al1ex/CVE-2021-22205 |
XTeam-Wing/CVE-2021-22205 | https://github.com/XTeam-Wing/CVE-2021-22205 |
r0eXpeR/CVE-2021-22205 | https://github.com/r0eXpeR/CVE-2021-22205 |
inspiringz/CVE-2021-22205 | https://github.com/inspiringz/CVE-2021-22205 |
whwlsfb/CVE-2021-22205 | https://github.com/whwlsfb/CVE-2021-22205 |
c0okB/CVE-2021-22205 | https://github.com/c0okB/CVE-2021-22205 |
Seals6/CVE-2021-22205 | https://github.com/Seals6/CVE-2021-22205 |
shang159/CVE-2021-22205-getshell | https://github.com/shang159/CVE-2021-22205-getshell |
runsel/GitLab-CVE-2021-22205- | https://github.com/runsel/GitLab-CVE-2021-22205- |
Name | URL |
---|---|
mr-r3bot/Gitlab-CVE-2021-22205 | github.com |
Al1ex/CVE-2021-22205 | github.com |
XTeam-Wing/CVE-2021-22205 | github.com |
r0eXpeR/CVE-2021-22205 | github.com |
inspiringz/CVE-2021-22205 | github.com |
whwlsfb/CVE-2021-22205 | github.com |
c0okB/CVE-2021-22205 | github.com |
Seals6/CVE-2021-22205 | github.com |
shang159/CVE-2021-22205-getshell | github.com |
runsel/GitLab-CVE-2021-22205- | github.com |