A critical unauthenticated, remote code execution GitLab flaw fixed on April 14, 2021, remains exploitable, with over 50% of deployments remaining unpatched. The vulnerability is tracked as CVE-2021-22205 and has a CVSS v3 score of 10.0. Hackers first started exploiting internet-facing GitLab servers in June 2021 to create new users and give them admin rights. The threat actors do not need to authenticate or use a CSRF token or even a valid HTTP endpoint to use the exploit.”]

