
11/4/2021 · GitLab
What this post added
This post addresses a critical security vulnerability (CVE-2021-22205) in self-managed GitLab instances caused by a third-party file parser (Exif-Tool). It details the affected versions, provides guidance on how to determine if an instance has been impacted, and strongly recommends upgrading to patched versions (13.10.3, 13.9.6, 13.8.8) or applying a hotpatch. It also directs users to forums and support channels for assistance and encourages subscription to security alerts.