← back
CVE-2022-2992criticalCWE-74

CVE-2022-2992

90Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 9.9epss 86%
from disclosure to weapon0 days
Published on NVDOct 17
1st PoCOct 8
metasploitOct 6
exploitation probability
86%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
GitLab · GitLab
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.