CVE-2022-2185
87Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 9.9epss 77%
from disclosure to weapon1 days
Published on NVDJul 1
1st PoC+1d
exploitation probability
77%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
GitLab · GitLabpublic PoCs found — 2
githubgithub.com/ESUAdmin/CVE-2022-2185★ 78githubgithub.com/safe3s/CVE-2022-2185-poc★ 13⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.