Critical severity10.0CISA KEVNVD Advisory· Published Apr 23, 2021· Updated Aug 6, 2026
CVE-2021-22205
CVE-2021-22205
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=11.9.0,<13.8.8
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=11.9.0,<13.8.8
- (no CPE)range: before 11.9
- (no CPE)range: >=11.9, <13.8.8
- Range: before 11.9
Patches
Vulnerability mechanics
References
6- packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22205.jsonnvdVendor Advisory
- hackerone.com/reports/1154542nvdPermissions RequiredThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/327121nvdBroken Link
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.