A AegiFlow
UNKNOWNKNOWN EXPLOITEDRANSOMWARE: KNOWN

CVE-2021-22205

GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

Published
2021-11-03
Modified
2026-07-31
Sources
cisa-kev

Summary

GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.