CVE-2022-2185: critical vulnerability in GitLab
Published · Updated
87Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 9.9epss 77%
from disclosure to weapon1 days
Published on NVDJul 1
1st PoC+1d
exploitation probability
77%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
GitLab · GitLabpublic PoCs found — 2
githubgithub.com/ESUAdmin/CVE-2022-2185★ 78githubgithub.com/safe3s/CVE-2022-2185-poc★ 13⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — GitLab
In the same product, most dangerous first.
CVE-2021-22205CRITICALCVE-2021-22205EPSS 99.7%KEVCVE-2023-7028CRITICALWeak Password Recovery Mechanism for Forgotten Password in GitLabEPSS 94.6%KEVCVE-2026-85706CRITICALImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLabEPSS 93.0%KEVCVE-2021-22175MEDIUMCVE-2021-22175EPSS 53.4%KEVCVE-2021-39935MEDIUMCVE-2021-39935EPSS 36.1%KEVCVE-2023-2442HIGHCVE-2023-2442EPSS 96.1%