Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-2884


A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint


Published

2022-10-17T16:15:21.453

Last Modified

2025-05-14T15:15:48.923

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.9 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-78
  • Type: Secondary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 15.1.5 Yes
Application gitlab gitlab < 15.1.5 Yes
Application gitlab gitlab < 15.2.3 Yes
Application gitlab gitlab < 15.2.3 Yes
Application gitlab gitlab < 15.3.1 Yes
Application gitlab gitlab < 15.3.1 Yes

References