CVE-2022-2884
Published on: Not Yet Published
Last Modified on: 10/19/2022 05:48:00 PM UTC
Certain versions of Gitlab from Gitlab contain the following vulnerability:
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint
- CVE-2022-2884 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- Affected Vendor/Software:
GitLab - GitLab version >=11.3.4, <15.1.5
- Affected Vendor/Software:
GitLab - GitLab version >=15.2, <15.2.3
- Affected Vendor/Software:
GitLab - GitLab version >=15.3, <15.3.1
CVSS3 Score: 9.9 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
HackerOne | hackerone.com text/html |
![]() |
2022/CVE-2022-2884.json · master · GitLab.org / cves · GitLab | gitlab.com text/html |
![]() |
RCE via github import (#371098) · Issues · GitLab.org / GitLab · GitLab | gitlab.com text/html |
![]() |
Related QID Numbers
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Gitlab | Gitlab | All | All | All | All |
Application | Gitlab | Gitlab | All | All | All | All |
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*:
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*:
Discovery Credit
Thanks [yvvdwf](https://hackerone.com/yvvdwf) for reporting this vulnerability through our HackerOne bug bounty program.
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
GitLab の Github インポートの処理に任意のコードを実行される問題 (CVE-2022-2884) [43142] sid.softek.jp/content/show/4… #SIDfm #脆弱性情報 | 2022-08-23 06:00:04 |
![]() |
CVE-2022-2884 - GitLab CE/EE allows an an authenticated user to achieve remote code execution via the Import from G… twitter.com/i/web/status/1… | 2022-08-23 08:29:00 |
![]() |
CVE-2022-2884: GitLab Remote Code Execution Vulnerability securityonline.info/cve-2022-2884-… #opensource #infosec #security #pentesting | 2022-08-23 12:27:05 |
![]() |
CVE-2022-2884: GitLab Remote Command Execution Vulnerability dlvr.it/SX5g2f via securityonline https://t.co/Pb49iQwDju | 2022-08-23 12:31:04 |
![]() |
#Vulnerability #CVE20222884 CVE-2022-2884: GitLab Remote Command Execution Vulnerability securityonline.info/cve-2022-2884-… | 2022-08-23 13:06:04 |
![]() |
"CVE-2022-2884: GitLab Remote Command Execution Vulnerability" via Penetration Testing ift.tt/FMsBK4g | 2022-08-23 13:23:02 |
![]() |
CVE-2022-2884: GitLab Remote Command Execution Vulnerability - securityonline.info/cve-2022-2884-… | 2022-08-23 13:38:40 |
![]() |
CVE-2022-2884 har-sia.info/CVE-2022-2884.… #HarsiaInfo | 2022-08-24 07:01:08 |
![]() |
CVE-2022-2884: GitLab Remote Command Execution Vulnerability securityonline.info/cve-2022-2884-… Penetration Testing CVE-2022… twitter.com/i/web/status/1… | 2022-08-24 07:14:00 |
![]() |
GitLab исправляет критическую уязвимость выполнения произвольного кода. CVE-2022-2884 (оценка CVSS: 9,9) затрагивае… twitter.com/i/web/status/1… | 2022-08-24 07:20:35 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884): GitLab has fixed a remote code execution vulnerab… twitter.com/i/web/status/1… | 2022-08-24 10:41:35 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) i.securitythinkingcap.com/SX8X3W https://t.co/UxgejYN5ju | 2022-08-24 10:41:37 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) - helpnetsecurity.com/2022/08/24/cve… - @gitlab #GitLab… twitter.com/i/web/status/1… | 2022-08-24 10:43:07 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) news.poseidon-us.com/SX8Ysv #PoseidonTPA… twitter.com/i/web/status/1… | 2022-08-24 10:57:34 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884): GitLab has fixed a remote code execution vulnerab… twitter.com/i/web/status/1… | 2022-08-24 11:02:14 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) dlvr.it/SX8dKl #news #cybersecurity… twitter.com/i/web/status/1… | 2022-08-24 11:19:04 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) bibstech.live/critical-rce-b… | 2022-08-24 11:29:00 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) itsecuritynews.info/critical-rce-b… | 2022-08-24 11:36:20 |
![]() |
helpnetsecurity.com/2022/08/24/cve… Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) #cybersecurity | 2022-08-24 11:41:05 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) dlvr.it/SX8hyw | 2022-08-24 11:46:08 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) helpnetsecurity.com/2022/08/24/cve… | 2022-08-24 11:51:07 |
![]() |
helpnetsecurity.com/2022/08/24/cve… Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) #cybersecurity | 2022-08-24 11:54:33 |
![]() |
#Critical RCE bug in GitLab patched, #update ASAP! (CVE-2022-2884) helpnetsecurity.com/2022/08/24/cve… #HelpNetSecurity | 2022-08-24 12:00:12 |
![]() |
ギットラボのRCEか helpnetsecurity.com/2022/08/24/cve… | 2022-08-24 12:17:15 |
![]() |
GitLab has released a security update to address a critical vulnerability (CVE-2022-2884) in its Community Edition… twitter.com/i/web/status/1… | 2022-08-24 12:23:16 |
![]() |
[Notice-CSA] GitLab has released a security update to address a critical vulnerability (CVE-2022-2884) in its Commu… twitter.com/i/web/status/1… | 2022-08-24 12:24:32 |
![]() |
Help Net Security | "Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884)" bit.ly/3POc4RI | 2022-08-24 12:28:41 |
![]() |
CVE-2022-2884: GitLab Remote Command Execution Vulnerability securityonline.info/cve-2022-2884-… | 2022-08-24 12:38:22 |
![]() |
Top 3 trending CVEs on Twitter Past 24 hrs: CVE-2022-2884: 184.7K (audience size) CVE-2022-2200: 157.7K CVE-2019-1… twitter.com/i/web/status/1… | 2022-08-24 13:00:03 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) - Help Net Security dlvr.it/SX92qc… twitter.com/i/web/status/1… | 2022-08-24 13:47:03 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) - Help Net Security - helpnetsecurity.com/2022/08/24/cve… | 2022-08-24 14:19:23 |
![]() |
CVE-2022-2884 har-sia.info/CVE-2022-2884.… #HarsiaInfo | 2022-08-24 15:00:08 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) securecybersolution.com/critical-rce-b… | 2022-08-24 15:00:14 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) helpnetsecurity.com/2022/08/24/cve… | 2022-08-24 15:06:59 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) #ciberseguridad #cibersecurity helpnetsecurity.com/2022/08/24/cve… | 2022-08-24 15:13:12 |
![]() |
@helpnetsecurity Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) @gitlab #GitLab #SecurityUpdate… twitter.com/i/web/status/1… | 2022-08-24 17:40:20 |
![]() |
GitLab Patch Critical RCE Flaws (CVE-2022-2884) CVSS: 9.9/10 bug.cyberkendra.com/2022/08/24/git… #security #GitLab | 2022-08-24 20:18:35 |
![]() |
RCE En GitLab ?? securityonline.info/cve-2022-2884-… | 2022-08-24 20:50:34 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) - Help Net Security helpnetsecurity.com/2022/08/24/cve… | 2022-08-25 00:36:30 |
![]() |
CVE - CVE-2022-2884 | 2022-08-25 05:42:56 |
![]() |
CVE-2022-2884 / CVSS v3 Base 9.9 // GitLab Critical Security Release: 15.3.1, 15.2.3, 15.1.5 | GitLab about.gitlab.com/releases/2022/… | 2022-08-25 07:40:31 |
![]() |
helpnetsecurity.com/2022/08/24/cve… | 2022-08-25 08:18:15 |
![]() |
?GitLabの重大なRCEバグのパッチがリリース:CVE-2022-2884 ?IBM、MQの深刻な脆弱性を修正:CVE-2022-27780、CVE-2022-30115 ⚠️Googleのソフトウェアアップデート装う新た… twitter.com/i/web/status/1… | 2022-08-25 09:10:21 |
![]() |
CVE-2022-2884 har-sia.info/CVE-2022-2884.… #HarsiaInfo | 2022-08-25 15:02:08 |
![]() |
#Qualys Threat Protection - GitLab Patches Critical Remote Command Execution Vulnerability (CVE-2022-2884)… twitter.com/i/web/status/1… | 2022-08-25 15:56:45 |
![]() |
RCE in GitLab installations via the Import from GitHub API endpoint (CVE-2022-2884) bleepingcomputer.com/news/security/… | 2022-08-25 17:32:21 |
![]() |
We are tracking CVE-2022-2884, a critical vulnerability affecting #GitLab, that allows an authenticated attacker to… twitter.com/i/web/status/1… | 2022-08-25 18:10:02 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) securecybersolution.com/critical-rce-b… #Sec_Cyber | 2022-08-26 08:01:13 |
![]() |
In this post, let’s see the summary, versions affected, and finally how to fix CVE-2022-2884, a critical authentica… twitter.com/i/web/status/1… | 2022-08-26 15:30:18 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884). helpnetsecurity.com/2022/08/24/cve… #infosec #cybersec #cybersecurity #RCE #gitlab | 2022-08-27 02:30:00 |
![]() |
GitLab command execution | CVE-2022-2884 - redpacketsecurity.com/gitlab-command… #CVE #Vulnerability #OSINT #ThreatIntel #Cyber | 2022-08-27 09:01:57 |
![]() |
اطلاعیه رسمی GitLab برای رفع یک آسیبپذیری حیاتی (CVE-2022-2884) در نسخه Community (CE) و Enterprise Edition (EE) ب… twitter.com/i/web/status/1… | 2022-08-28 10:31:09 |
![]() |
#gitlab RCE is critical CVE-2022-2884. Urgent Update Required #apisecurity #injections lnkd.in/gzQN3wDQ It… twitter.com/i/web/status/1… | 2022-08-28 15:07:44 |
![]() |
[email protected] is tracking CVE-2022-2884, a critical vulnerability affecting GitLab, allowing an authenticated attacke… twitter.com/i/web/status/1… | 2022-08-30 16:07:44 |
![]() |
#HelpNetSecurity #CyberSecurity #Automated | Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) helpnetsecurity.com/2022/08/24/cve… | 2022-08-30 18:47:06 |
![]() |
GitLab の深刻な脆弱性 CVE-2022-2884 が FIX:認証済みの攻撃者による RCE #security #vulnerability #gitlab iototsecnews.jp/2022/08/23/git… | 2022-08-30 22:18:05 |
![]() |
[email protected] is tracking CVE-2022-2884, a critical vulnerability affecting GitLab, allowing an authenticated attacke… twitter.com/i/web/status/1… | 2022-08-31 16:03:41 |
![]() |
GitLab issued patches for a critical RCE vulnerability (CVE-2022-2884), impacting both Community and Enterprise edi… twitter.com/i/web/status/1… | 2022-09-06 14:00:01 |
![]() |
[email protected] is tracking CVE-2022-2884, a critical vulnerability affecting GitLab, allowing an authenticated attacke… twitter.com/i/web/status/1… | 2022-09-07 17:17:15 |
![]() |
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884): GitLab has… dlvr.it/SY5tkr @RedSeal_co… twitter.com/i/web/status/1… | 2022-09-10 17:43:34 |
![]() |
GitLab issued patches for a critical RCE vulnerability (CVE-2022-2884), impacting both Community and Enterprise edi… twitter.com/i/web/status/1… | 2022-09-21 18:30:00 |
![]() |
CVE-2022-2884 : A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3,… twitter.com/i/web/status/1… | 2022-10-17 16:14:57 |
![]() |
CVE-2022-2884 (9.9/10), beware if you're using certificate-based integration with Kubernetes | 2022-08-23 07:20:27 |
![]() |
CVE-2022-2884: GitLab Remote Command Execution Vulnerability | 2022-08-23 13:06:05 |
![]() |
DevOps platform GitLab has released security updates to fix a critical remote code execution vulnerability, tracked as CVE-2022-2884 (CVSS 9.9), affecting its GitLab Community Edition (CE) and Enterprise Edition (EE) releases. | 2022-08-24 02:58:59 |
![]() |
CVE-2022-2884 | 2022-10-17 17:38:42 |