peter bassill · operator
$ cve CVE-2022-2884 JSON

CVE-2022-2884 EXPLOIT

9.9
CRITICAL · CVSS 3.1 · EPSS 75.7% (pctl 100)

Patch early

A public exploit exists.

Description

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

Scoring

CVSS9.9 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS75.72% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2022-10-17
Last modified2026-06-17

Affected (1)

VendorProduct
gitlabgitlab

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD