← Back to browse · API

CVE-2022-2992

Severity
CRITICAL
CVSS
9.9
EPSS
0.86194
Risk score
69.77
CISA KEV
No
PoC
No
Published
2022-10-17
Modified
2025-05-14
First seen
2026-08-07
Aliases
EUVD-2022-35210, GHSA-M7F3-552R-PF23
Products
GitLab:GitLab 11.10, <15.1.6, GitLab:GitLab 15.2, <15.2.4, GitLab:GitLab 15.3, <15.3.2
Sources
euvd EUVD-2022-35210

Description

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

References