CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.
Remediation Deadline: Nov 17, 2021
CVE-2021-22205
High
CVSS 10EPSS 94.5%CISA KEVPoC AvailableRansomwareDescription
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.
CVSS Score
10/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HEPSS — Exploit Probability
94.5%
Higher than 100.0% of all CVEs
Weakness Classification (CWE)
Known Exploits
POChttp://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.htmlExploithttp://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.htmlExploithttp://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.htmlExploithttp://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.htmlExploit
Required Action
https://nvd.nist.gov/vuln/detail/CVE-2021-22205
Risk Assessment
CRITICALIn CISA KEV
Known exploit
Critical CVSS
High EPSS
Ransomware
Details
- Severity
- High
- CVSS
- 10
- EPSS
- 94.5%
- CWE
- CWE-94
- Exploit
- POC
- CISA KEV
- Yes
- Ransomware
- Known
- Articles
- 0
Timeline
Published
Nov 3, 2021
Added to KEV
Nov 3, 2021
Remediation Due
Nov 17, 2021