ZeroHour

CVE-2022-2992

CVSS 3.1
9.9 critical
EPSS
86%p100
Published
()
Modified
Description

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

Vendors
gitlab
Products
gitlab
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.