CVE-2021-22205 - log back

CVE-2021-22205 edited at 28 Apr 2021 11:15:40
Description
- An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that is passed to a file parser which resulted in a remote command execution. The issue is fixed in GitLab versions 13.10.3, 13.9.6 and 13.8.8.
+ An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that is passed to a file parser which resulted in a remote command execution. The issue is fixed in GitLab versions 13.10.3, 13.9.6 and 13.8.8.
CVE-2021-22205 edited at 24 Apr 2021 08:24:30
Severity
- Unknown
+ Critical
Remote
- Unknown
+ Remote
Type
- Unknown
+ Arbitrary code execution
Description
+ An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that is passed to a file parser which resulted in a remote command execution. The issue is fixed in GitLab versions 13.10.3, 13.9.6 and 13.8.8.
References
+ https://about.gitlab.com/releases/2021/04/14/security-release-gitlab-13-10-3-released/#Remote-code-execution-when-uploading-specially-crafted-image-files
+ https://gitlab.com/gitlab-org/gitlab/-/issues/327121
+ https://hackerone.com/reports/1154542
CVE-2021-22205 created at 24 Apr 2021 08:23:02
Severity
+ Unknown
Remote
+ Unknown
Type
+ Unknown
Description
References
Notes