peter bassill · operator
$ cve CVE-2022-2992 JSON

CVE-2022-2992

9.9
CRITICAL · CVSS 3.1 · EPSS 86.2% (pctl 100)

Patch early

EPSS 86.2% — above the 10% action threshold.

Description

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

Scoring

CVSS9.9 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS86.19% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-74
On CISA KEVno
Public exploitnone known
Published2022-10-17
Last modified2026-06-17

Affected (1)

VendorProduct
gitlabgitlab

References

→ the Explorer  ·  watch your stack  ·  NVD