Related Vulnerabilities: CVE-2021-22192  

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary code on the server.

Severity Critical

Remote Yes

Type Arbitrary code execution

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary code on the server.

AVG-1710 gitlab 13.9.3-1 13.9.4-1 Critical Fixed

https://about.gitlab.com/releases/2021/03/17/security-release-gitlab-13-9-4-released/#remote-code-execution-via-unsafe-user-controlled-markdown-rendering-options
https://hackerone.com/reports/1125425
https://gitlab.com/gitlab-org/gitlab/-/issues/324452
https://gitlab.com/gitlab-org/gitlab/-/commit/179329b5c3c118924fb242dc449d06b4ed6ccb66