VDB
BDU%3A2021-05738
BDU%3A2021-05738
PUBLISHED
CVSS 6.5 MEDIUM
Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с недостаточной проверкой входных данных, позволяющая нарушителю выполнить произвольные команды
Risk Scores
CVSS 2.0
6.5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| GitLab Inc. | Gitlab |
Timeline
- Dec 1, 2021 CVE Published
- Feb 6, 2022 PoC Published
- Jul 15, 2022 PoC Published
- Sep 16, 2022 PoC Published
- Nov 1, 2022 PoC Published
- Mar 1, 2024 PoC Published
- Jul 17, 2024 PoC Published
- Sep 24, 2024 CVE Updated
- May 9, 2025 PoC Published
- Jul 26, 2025 PoC Published
- Sep 30, 2025 PoC Published
- Oct 29, 2025 PoC Published
References
- http://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.html url
- http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.html url
- https://gitlab.com/gitlab-org/gitlab/-/issues/327121 url
- https://hackerone.com/reports/1154542 url
- https://nvd.nist.gov/vuln/detail/CVE-2021-22205 url
- https://github.com/RedTeamWing/CVE-2021-22205 url
- https://github.com/Al1ex/CVE-2021-22205 url
- https://www.cisa.gov/sites/default/files/csv/known_exploited_vulnerabilities.csv url
- https://github.com/mr-r3bot/Gitlab-CVE-2021-22205 advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22205.json advisory