CVE-2022-2884
9.9
CRITICAL
CVSS 3.1
EPSS 75.7%
Description
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint
How to fix CVE-2022-2884
To remediate CVE-2022-2884, upgrade the affected package to a fixed version below.
- Bitnami/gitlab—upgrade to 15.1.5 or later
Is CVE-2022-2884 being exploited?
Likely — EPSS is 75.7%, placing CVE-2022-2884 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- >= 11.3.4, < 15.1.5, >= 15.2.0, < 15.2.3, >= 15.3.0, < 15.3.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.9 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |