CVE-2021-22205

GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

10.0
CVSS 3.1
99.7 %
EPSS (current)
2021-11-03
KEV addition
Yes
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: GitLab / Community and Enterprise Editions

Published: 2021-04-23 · Due (CISA): 2021-11-17

CWE: CWE-94 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
nucleihttp/cves/2021/CVE-2021-22205.yamlGitLab CE/EE - Remote Code Execution–
metasploitexploit/multi/http/gitlab_exif_rceexploit/multi/http/gitlab_exif_rce2021-04-14
exploitdb50532GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated)2021-11-17

References only — no downloads or instructions.

Sources