← Back to browse · API

CVE-2022-2884

Severity
CRITICAL
CVSS
9.9
EPSS
0.75718
Risk score
66.1
CISA KEV
No
PoC
No
Published
2022-10-17
Modified
2025-05-14
First seen
2026-08-07
Aliases
EUVD-2022-35116, GHSA-MJCR-H6W7-XCX6
Products
GitLab:GitLab 11.3.4, <15.1.5, GitLab:GitLab 15.2, <15.2.3, GitLab:GitLab 15.3, <15.3.1
Sources
euvd EUVD-2022-35116

Description

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

References