Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2021-22205

Quick assessment

Affected
GitLab GitLab
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GitLab是美国GitLab公司的一个开源的端到端软件开发平台,具有内置的版本控制、问题跟踪、代码审查、CI/CD(持续集成和持续交付)等功能。 Gitlab Community Edition 存在代码注入漏洞,该漏洞源于图像解析器在处理图像文件时输入验证不正确。以下产品及版本受到影响::Gitlab Community Edition: 11.9.0, 11.9.1, 11.9.2, 11.9.3, 11.9.4, 11.9.5, 11.9.6, 11.9.7, 11.9.8, 11.9.9, 11

CVSS 10.0 · Critical KEV · Ransomware EPSS 99.73% · P100

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 3

VendorProduct Version RangeStatus
GitLab GitLab >=11.9, <13.8.8 affected
>=13.9, <13.9.6 affected
>=13.10, <13.10.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-22205

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
GitLab 代码注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GitLab是美国GitLab公司的一个开源的端到端软件开发平台,具有内置的版本控制、问题跟踪、代码审查、CI/CD(持续集成和持续交付)等功能。 Gitlab Community Edition 存在代码注入漏洞,该漏洞源于图像解析器在处理图像文件时输入验证不正确。以下产品及版本受到影响::Gitlab Community Edition: 11.9.0, 11.9.1, 11.9.2, 11.9.3, 11.9.4, 11.9.5, 11.9.6, 11.9.7, 11.9.8, 11.9.9, 11
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
GitLab GitLab >=11.9, <13.8.8 -

II. Public POCs for CVE-2021-22205

# POC Description Source Link Shenlong Link
1 None https://github.com/mr-r3bot/Gitlab-CVE-2021-22205 POC Details
2 Pocsuite3 For CVE-2021-22205 https://github.com/XTeam-Wing/CVE-2021-22205 POC Details
3 CVE-2021-22205 Unauthorized RCE https://github.com/r0eXpeR/CVE-2021-22205 POC Details
4 Gitlab CE/EE RCE 未授权远程代码执行漏洞 POC && EXP CVE-2021-22205 https://github.com/antx-code/CVE-2021-22205 POC Details
5 CVE-2021-22205& GitLab CE/EE RCE https://github.com/Al1ex/CVE-2021-22205 POC Details
6 CVE-2021-22205 Gitlab 未授权远程代码执行漏洞 EXP, 移除了对djvumake & djvulibre的依赖,可在win平台使用 https://github.com/whwlsfb/CVE-2021-22205 POC Details
7 PoC in single line bash https://github.com/findneo/GitLab-preauth-RCE_CVE-2021-22205 POC Details
8 CVE-2021-22205未授权漏洞批量检测与利用工具 https://github.com/Seals6/CVE-2021-22205 POC Details
9 CVE-2021-22205 RCE https://github.com/c0okB/CVE-2021-22205 POC Details
10 CVE-2021-22205-getshell https://github.com/shang159/CVE-2021-22205-getshell POC Details
11 CVE-2021-22205& GitLab CE/EE RCE https://github.com/devdanqtuan/CVE-2021-22205 POC Details
12 None https://github.com/hh-hunter/cve-2021-22205 POC Details
13 Automated Gitlab RCE via CVE-2021-22205 https://github.com/X1pe0/Automated-Gitlab-RCE POC Details
14 Exploit for GitLab CVE-2021-22205 Unauthenticated Remote Code Execution https://github.com/runsel/GitLab-CVE-2021-22205- POC Details
15 None https://github.com/faisalfs10x/GitLab-CVE-2021-22205-scanner POC Details
16 GitLab CE/EE Preauth RCE using ExifTool https://github.com/inspiringz/CVE-2021-22205 POC Details
17 A CVE-2021-22205 Gitlab RCE POC written in Golang https://github.com/pizza-power/Golang-CVE-2021-22205-POC POC Details
18 NSE script to fingerprint if GitLab is vulnerable to cve-2021-22205-nse https://github.com/DIVD-NL/GitLab-cve-2021-22205-nse POC Details
19 CVE-2021-22205 的批量检测脚本 https://github.com/w0x68y/Gitlab-CVE-2021-22205 POC Details
20 None https://github.com/al4xs/CVE-2021-22205-gitlab POC Details
21 None https://github.com/honypot/CVE-2021-22205 POC Details
22 GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated) cve-2021-22205 https://github.com/momika233/cve-2021-22205-GitLab-13.10.2---Remote-Code-Execution-RCE-Unauthenticated- POC Details
23 CVE-2021-22205 检测脚本,支持getshell和命令执行 https://github.com/keven1z/CVE-2021-22205 POC Details
24 None https://github.com/hhhotdrink/CVE-2021-22205 POC Details
25 None https://github.com/sei-fish/CVE-2021-22205 POC Details
26 None https://github.com/overgrowncarrot1/DejaVu-CVE-2021-22205 POC Details
27 None https://github.com/Hikikan/CVE-2021-22205 POC Details
28 A simple bash script that exploits CVE-2021-22205 against vulnerable instances of gitlab https://github.com/NukingDragons/gitlab-cve-2021-22205 POC Details
29 CVE-2021-22205 exploit script https://github.com/cc3305/CVE-2021-22205 POC Details
30 Gitlab CE/EE RCE 未授权远程代码执行漏洞 POC && EXP CVE-2021-22205 https://github.com/ZZ-SOCMAP/CVE-2021-22205 POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-22205

请登录查看更多情报信息。

Exploits & Public PoCs for CVE-2021-22205 (2)

Other References for CVE-2021-22205 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2021-22205

No comments yet


Leave a comment