目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2021-22205— GitLab 代码注入漏洞

一分钟漏洞结论

影响对象
GitLab GitLab
利用判断
已确认在野利用,应立即处置
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

GitLab是美国GitLab公司的一个开源的端到端软件开发平台,具有内置的版本控制、问题跟踪、代码审查、CI/CD(持续集成和持续交付)等功能。 Gitlab Community Edition 存在代码注入漏洞,该漏洞源于图像解析器在处理图像文件时输入验证不正确。以下产品及版本受到影响::Gitlab Community Edition: 11.9.0, 11.9.1, 11.9.2, 11.9.3, 11.9.4, 11.9.5, 11.9.6, 11.9.7, 11.9.8, 11.9.9, 11

CVSS 10.0 · Critical KEV · 勒索软件 EPSS 99.73% · P100

影响版本矩阵 3

厂商产品 版本范围状态
GitLab GitLab >=11.9, <13.8.8 affected
>=13.9, <13.9.6 affected
>=13.10, <13.10.3 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2021-22205 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: CVE Program / CVE List V5
Vulnerability Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
GitLab 代码注入漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
GitLab是美国GitLab公司的一个开源的端到端软件开发平台,具有内置的版本控制、问题跟踪、代码审查、CI/CD(持续集成和持续交付)等功能。 Gitlab Community Edition 存在代码注入漏洞,该漏洞源于图像解析器在处理图像文件时输入验证不正确。以下产品及版本受到影响::Gitlab Community Edition: 11.9.0, 11.9.1, 11.9.2, 11.9.3, 11.9.4, 11.9.5, 11.9.6, 11.9.7, 11.9.8, 11.9.9, 11
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

厂商 产品 影响版本 CPE 订阅
GitLab GitLab >=11.9, <13.8.8 -

二、漏洞 CVE-2021-22205 的公开POC

# POC 描述 源链接 神龙链接
1 None https://github.com/mr-r3bot/Gitlab-CVE-2021-22205 POC详情
2 Pocsuite3 For CVE-2021-22205 https://github.com/XTeam-Wing/CVE-2021-22205 POC详情
3 CVE-2021-22205 Unauthorized RCE https://github.com/r0eXpeR/CVE-2021-22205 POC详情
4 Gitlab CE/EE RCE 未授权远程代码执行漏洞 POC && EXP CVE-2021-22205 https://github.com/antx-code/CVE-2021-22205 POC详情
5 CVE-2021-22205& GitLab CE/EE RCE https://github.com/Al1ex/CVE-2021-22205 POC详情
6 CVE-2021-22205 Gitlab 未授权远程代码执行漏洞 EXP, 移除了对djvumake & djvulibre的依赖,可在win平台使用 https://github.com/whwlsfb/CVE-2021-22205 POC详情
7 PoC in single line bash https://github.com/findneo/GitLab-preauth-RCE_CVE-2021-22205 POC详情
8 CVE-2021-22205未授权漏洞批量检测与利用工具 https://github.com/Seals6/CVE-2021-22205 POC详情
9 CVE-2021-22205 RCE https://github.com/c0okB/CVE-2021-22205 POC详情
10 CVE-2021-22205-getshell https://github.com/shang159/CVE-2021-22205-getshell POC详情
11 CVE-2021-22205& GitLab CE/EE RCE https://github.com/devdanqtuan/CVE-2021-22205 POC详情
12 None https://github.com/hh-hunter/cve-2021-22205 POC详情
13 Automated Gitlab RCE via CVE-2021-22205 https://github.com/X1pe0/Automated-Gitlab-RCE POC详情
14 Exploit for GitLab CVE-2021-22205 Unauthenticated Remote Code Execution https://github.com/runsel/GitLab-CVE-2021-22205- POC详情
15 None https://github.com/faisalfs10x/GitLab-CVE-2021-22205-scanner POC详情
16 GitLab CE/EE Preauth RCE using ExifTool https://github.com/inspiringz/CVE-2021-22205 POC详情
17 A CVE-2021-22205 Gitlab RCE POC written in Golang https://github.com/pizza-power/Golang-CVE-2021-22205-POC POC详情
18 NSE script to fingerprint if GitLab is vulnerable to cve-2021-22205-nse https://github.com/DIVD-NL/GitLab-cve-2021-22205-nse POC详情
19 CVE-2021-22205 的批量检测脚本 https://github.com/w0x68y/Gitlab-CVE-2021-22205 POC详情
20 None https://github.com/al4xs/CVE-2021-22205-gitlab POC详情
21 None https://github.com/honypot/CVE-2021-22205 POC详情
22 GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated) cve-2021-22205 https://github.com/momika233/cve-2021-22205-GitLab-13.10.2---Remote-Code-Execution-RCE-Unauthenticated- POC详情
23 CVE-2021-22205 检测脚本,支持getshell和命令执行 https://github.com/keven1z/CVE-2021-22205 POC详情
24 None https://github.com/hhhotdrink/CVE-2021-22205 POC详情
25 None https://github.com/sei-fish/CVE-2021-22205 POC详情
26 None https://github.com/overgrowncarrot1/DejaVu-CVE-2021-22205 POC详情
27 None https://github.com/Hikikan/CVE-2021-22205 POC详情
28 A simple bash script that exploits CVE-2021-22205 against vulnerable instances of gitlab https://github.com/NukingDragons/gitlab-cve-2021-22205 POC详情
29 CVE-2021-22205 exploit script https://github.com/cc3305/CVE-2021-22205 POC详情
30 Gitlab CE/EE RCE 未授权远程代码执行漏洞 POC && EXP CVE-2021-22205 https://github.com/ZZ-SOCMAP/CVE-2021-22205 POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2021-22205 的情报信息

请登录查看更多情报信息。

CVE-2021-22205 公开利用代码 (2)

CVE-2021-22205 其他参考 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2021-22205

暂无评论


发表评论