I feel like this article could have been far more useful with the following points being explicitly mentioned, or at least summarized: - the problem appeared in GitLab 11.9.0 - the problem seems to have been fixed in GitLab 13.8.8 - the vulnerability uses ExifTool, so to exploit it, a user needs to be able to upload images - if an update is not (yet) possible, DjVu format file uploads can be blocked to avert this vul…
How do you check if you have been compromised? I did apply the patch a few days after it was released, but im unsure if the system has been compromised....
Please see this post on the GitLab forum for details how you can determine if your instance has been compromised through the exploitation of CVE-2021-22205: https://forum.gitlab.com/t/cve-2021-22205-how-to-determine-i...