CVE-2021-22204

MEDIUM KEV LAB

GitLab Unauthenticated Remote ExifTool Command Injection

Title source: metasploit

Description

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

Exploits (20)

exploitdb WORKING POC
by UNICORD · pythonlocallinux
https://www.exploit-db.com/exploits/50911
nomisec WORKING POC 94 stars
by convisolabs · client-side
https://github.com/convisolabs/CVE-2021-22204-exiftool
nomisec WORKING POC 50 stars
by UNICORDev · local
https://github.com/UNICORDev/exploit-CVE-2021-22204
nomisec WORKING POC 28 stars
by AssassinUKG · poc
https://github.com/AssassinUKG/CVE-2021-22204
nomisec WORKING POC 12 stars
by se162xg · client-side
https://github.com/se162xg/CVE-2021-22204
nomisec WORKING POC 8 stars
by bilkoh · client-side
https://github.com/bilkoh/POC-CVE-2021-22204
nomisec WORKING POC 4 stars
by Akash7350 · client-side
https://github.com/Akash7350/CVE-2021-22204
nomisec WRITEUP 3 stars
by trganda · poc
https://github.com/trganda/CVE-2021-22204
nomisec WORKING POC 3 stars
by PenTestical · poc
https://github.com/PenTestical/CVE-2021-22204
nomisec WORKING POC 2 stars
by ph-arm · remote-auth
https://github.com/ph-arm/CVE-2021-22204-Gitlab
nomisec WORKING POC
by Roronoawjd · local
https://github.com/Roronoawjd/CVE-2021-22204
nomisec WORKING POC
by cc3305 · client-side
https://github.com/cc3305/CVE-2021-22204
nomisec WORKING POC
by battleofthebots · client-side
https://github.com/battleofthebots/dejavu
nomisec WORKING POC
by Asaad27 · poc
https://github.com/Asaad27/CVE-2021-22204-RSE
vulncheck_xdb WORKING POC
local
https://github.com/BBurgarella/An-Ethical-Hacking-Journey
vulncheck_xdb WORKING POC
local
https://github.com/mr-tuhin/CVE-2021-22204-exiftool
vulncheck_xdb WORKING POC
client-side
https://github.com/0xBruno/CVE-2021-22204
metasploit WORKING POC EXCELLENT
by William Bowling, Justin Steven · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/fileformat/exiftool_djvu_ant_perl_injection.rb

References (15)

Scores

CVSS v3 6.8
EPSS 0.9286
EPSS Percentile 99.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

Lab Environment

COMMUNITY
Community Lab
docker pull ghcr.io/battleofthebots/botb-base-image:ubuntu
+14 more repos

Details

CISA KEV 2021-11-17
VulnCheck KEV 2021-09-30
InTheWild.io 2021-11-17
ENISA EUVD EUVD-2021-9350
CWE
CWE-94
Status published
Products (6)
debian/debian_linux 9.0
debian/debian_linux 10.0
exiftool_project/exiftool 7.44 - 12.24
fedoraproject/fedora 32
fedoraproject/fedora 33
fedoraproject/fedora 34
Published Apr 23, 2021
KEV Added Nov 17, 2021
Tracked Since Feb 18, 2026