GitLab CE 13.10.1, vulnerable to CVE-2021-22205: images uploaded to some endpoints are passed to ExifTool, whose DjVu annotation parser evaluates Perl, so an unauthenticated upload runs commands.
Not startedDockercommit 344d855x86_64 · aarch64Secret
Exploit CVE-2021-22205 to run a command on the GitLab server without logging in.
The brief for this lab lives in its repository.