An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary code on the server.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/EdgeSecurityTeam/Vulnerability
- https://github.com/PetrusViet/Gitlab-RCE
- https://github.com/lyy289065406/CVE-2021-22192
- https://github.com/lyy289065406/lyy289065406
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/tzwlhack/Vulnerability