Action needed by self-managed customers in response to CVE-2021-22205

· · Nov. 4, 2021, 5:44 p.m.
Summary
CVE-2021-22205 is a critical severity vulnerability (CVSS 10.0) that is a result of improper validation of image files by a 3rd-party file parser Exif-Tool, resulting in a remote command execution vulnerability that can lead to the compromise of your GitLab instance. We have confirmed reports of the vulnerability being exploited on self-hosted public-facing GitLab instances. GitLab versions affected by CVE-2021-22205: Self-managed customers running the following GitLab versions are vulnerable to...
AUTHOR