Description
Due to a vulnerablility in ExifTool, GitLab was not properly validating image files which resulted in a remote command execution.
Remediation
Upgrade to the latest version of GitLab
References
Related Vulnerabilities
Palo Alto PAN-OS Management Interface Auth Bypass (CVE-2024-0012/CVE-2024-9474)
Oracle WebLogic Remote Code Execution (CVE-2020-14882)
Liferay TunnelServlet Deserialization Remote Code Execution
WordPress Plugin WP-Live Chat by 3CX Remote Code Execution (7.0.01)
WordPress Plugin Arigato Autoresponder and Newsletter Remote Code Execution (2.5.1.9)