Fiche vulnérabilité
CVE-2021-22205 : faille exploitée gitlab gitlab (CVSS 10.0)
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
En bref
- Sévérité
- Critique (CVSS 10.0)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Exploitation active
- Oui, inscrite au catalogue CISA KEV
- Publication
- 23 avr. 2021
- Dernière mise à jour
- 6 août 2026
Produits concernés
- gitlab gitlab
Correctif et mesures
Apply updates per vendor instructions.