An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates
https://www.darkreading.com/threat-intelligence/earth-lamia-exploits-sql-rce-bugs-asia
https://thehackernews.com/2025/05/china-linked-hackers-exploit-sap-and.html
https://www.securityweek.com/chinese-hacking-group-earth-lamia-targets-multiple-industries/
https://www.trendmicro.com/en_us/research/25/e/earth-lamia.html
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a
https://blog.xlab.qianxin.com/catddos-derivative-en/
https://thehackernews.com/2023/12/behind-scenes-of-matveevs-ransomware.html
https://therecord.media/confluence-and-gitlab-servers-targeted-by-new-ransomware-strain
https://github.com/Athology0000/cve-lab
https://github.com/korneevscp/osint-target
https://github.com/K3ysTr0K3R/CVE-2021-22205
https://github.com/AhmetPayaslioglu/web-log-anomaly-detector
https://github.com/flags-alt/abyss-c2
https://github.com/phantom-offensive/AppAssault
https://github.com/phantom-offensive/AppAssaultLab
https://github.com/Phantom-C2-77/AppAssaultLab
https://github.com/ccordeiro/CVE-2021-22205
https://github.com/ThatTotallyRealMyth/Exploits-CVEs
https://github.com/cyberwithcyril/VulhubPenTestingReport
https://github.com/g1san/Agents-for-Vulnerable-Dockers-and-related-Benchmarks
https://github.com/0xget/cve-2001-1473
https://github.com/Loginsoft-Research/Linux-Exploit-Detection
https://github.com/34zY/APT-Backpack
https://github.com/Schira4396/VcenterKiller
https://github.com/keven1z/CVE-2021-22205
https://github.com/cc3305/CVEAllTheThings
https://github.com/GitLab-Red-Team/cve-hash-harvester
https://github.com/GitLab-Red-Team/cve-2021-22205-hash-harvester
https://github.com/gardenWhy/Gitlab-CVE-2021-22205
https://github.com/awsassets/CVE-2021-22210
https://github.com/ahmad4fifz/CVE-2021-22205
https://github.com/runsel/GitLab-CVE-2021-22205-
https://github.com/X1pe0/Automated-Gitlab-RCE
https://github.com/devdanqtuan/CVE-2021-22205
https://github.com/shang159/CVE-2021-22205-getshell
https://github.com/c0okB/CVE-2021-22205
https://github.com/Seals6/CVE-2021-22205
https://github.com/whwlsfb/CVE-2021-22205
https://github.com/Al1ex/CVE-2021-22205
https://github.com/XTeam-Wing/CVE-2021-22205
https://github.com/Bin4xin/bigger-than-bigger
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22205
https://gitlab.com/gitlab-org/gitlab/-/issues/327121
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22205.json
http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.html