← back
CVE-2022-2884criticalCWE-78

CVE-2022-2884

72Vexday Risk Score

Keep watching. It has a public proof of concept.

ssvc Attendcvss 9.9epss 76%
from disclosure to weapon66 days
Published on NVDOct 17
1st PoC+66d
exploitation probability
76%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
GitLab · GitLab
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.