CVE-2022-2992
9.9
CRITICAL · CVSS 3.1 · EPSS 86.2% (pctl 100)
Patch early
EPSS 86.2% — above the 10% action threshold.
Description
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.
Scoring
| CVSS | 9.9 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 86.19% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-74 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-10-17 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| gitlab | gitlab |
References
- http://packetstormsecurity.com/files/171008/GitLab-GitHub-Repo-Import-Deserialization-Remote-Code-Execution.html
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2992.json
- https://gitlab.com/gitlab-org/gitlab/-/issues/371884
- https://hackerone.com/reports/1679624
- http://packetstormsecurity.com/files/171008/GitLab-GitHub-Repo-Import-Deserialization-Remote-Code-Execution.html
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2992.json
- https://gitlab.com/gitlab-org/gitlab/-/issues/371884
- https://hackerone.com/reports/1679624
→ the Explorer · watch your stack · NVD