'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2026-05-06 | |
| Rule Name: | GitLab Remote Code Execution Vulnerability (CVE-2021-22205) | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | GitLab is an open-source end-to-end software development platform by GitLab Inc., featuring built-in version control, issue tracking, code review, CI/CD (Continuous Integration/Continuous Delivery), and other functionalities. An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution. | |
| Impact: | Successful exploitation allows an attacker to execute arbitrary system commands on the GitLab server, leading to complete system compromise, data theft, lateral movement, and potential access to sensitive Git repositories and CI/CD pipelines. | |
| Affected OS: | Linux | |
| Reference: | CVE-2021-22205 |
|
| Solutions |
|---|
| Please refer to announcements or patches release by the vendor: https://about.gitlab.com/releases/2021/04/14/security-release-gitlab-13-10-3-released/ |