CVE-2022-2884 EXPLOIT
9.9
CRITICAL · CVSS 3.1 · EPSS 75.7% (pctl 100)
Patch early
A public exploit exists.
Description
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint
Scoring
| CVSS | 9.9 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 75.72% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2022-10-17 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| gitlab | gitlab |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | GitLab v15.3 - Remote Code Execution (RCE) (Authenticated) | 2023-04-01 |
References
- http://packetstormsecurity.com/files/171628/GitLab-15.3-Remote-Code-Execution.html
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2884.json
- https://gitlab.com/gitlab-org/gitlab/-/issues/371098
- https://hackerone.com/reports/1672388
- http://packetstormsecurity.com/files/171628/GitLab-15.3-Remote-Code-Execution.html
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2884.json
- https://gitlab.com/gitlab-org/gitlab/-/issues/371098
- https://hackerone.com/reports/1672388
→ the Explorer · watch your stack · NVD