CVE-2021-22204
KEVHIGH 7.8EPSS 100.0%
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 6.8 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 99.98% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-17
- Published
- 2021-04-23
- Updated
- 2025-10-21
Proof-of-concept exploits (28)
- http://packetstormsecurity.com/files/162558/ExifTool-DjVu-ANT-Perl-Injection.html
- http://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Comman…
- http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/167038/ExifTool-12.23-Arbitrary-Code-Execution.html
- 0xBruno/CVE-2021-222042★ · 2022-01-30
- Akash7350/CVE-2021-222044★ · 2023-05-14
- Asaad27/CVE-2021-22204-RSE0★ · 2021-12-08
- AssassinUKG/CVE-2021-2220427★ · 2021-10-26
- CsEnox/Gitlab-Exiftool-RCE61★ · 2021-06-04
- EternalDreamer01/RCE-exploit-Gitlab-13.9.10★ · 2024-06-22
- LazyTitan33/ExifTool-DjVu-exploit1★ · 2023-01-10
- MikeCod/RCE-exploit-Gitlab-13.9.10★ · 2024-06-22
- PenTestical/CVE-2021-222043★ · 2021-08-02
- PolGs/htb-meta0★ · 2022-06-01
- UNICORDev/exploit-CVE-2021-2220455★ · 2025-01-14
- bilkoh/POC-CVE-2021-222048★ · 2021-05-21
- cc3305/CVE-2021-222040★ · 2024-06-19
- convisolabs/CVE-2021-22204-exiftool96★ · 2021-05-20
- mr-r3bot/Gitlab-CVE-2021-22205181★ · 2021-11-02
- mr-tuhin/CVE-2021-22204-exiftool9★ · 2022-02-21
- oneoy/Gitlab-Exiftool-RCE0★ · 2021-11-05
- ph-arm/CVE-2021-22204-Gitlab2★ · 2021-11-04
- pizza-power/Golang-CVE-2021-22205-POC3★ · 2021-11-25
- se162xg/CVE-2021-2220412★ · 2021-05-12
- szTheory/exifcleaner2650★ · 2026-08-24
- trganda/CVE-2021-222043★ · 2021-12-29
- Roronoawjd/CVE-2021-22204
- d4ytox/CVE-2021-22204