PoC Index

CVE-2022-2992

CRITICAL 9.9EPSS 86.2%

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

CVSS v3.1
9.9 CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v3.1
9.9 CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS
86.19% chance of exploitation in the next 30 days, 100th percentile
Published
2022-10-17
Updated
2025-05-14

Proof-of-concept exploits (3)

Metasploit modules (1)

Exploit collections (1)

References

Related