CVE-2022-2884

Published on: Not Yet Published

Last Modified on: 10/19/2022 05:48:00 PM UTC

AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Certain versions of Gitlab from Gitlab contain the following vulnerability:

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

  • CVE-2022-2884 has been assigned by URL Logo [email protected] to track the vulnerability - currently rated as CRITICAL severity.
  • Affected Vendor/Software: URL Logo GitLab - GitLab version >=11.3.4, <15.1.5
  • Affected Vendor/Software: URL Logo GitLab - GitLab version >=15.2, <15.2.3
  • Affected Vendor/Software: URL Logo GitLab - GitLab version >=15.3, <15.3.1

CVSS3 Score: 9.9 - CRITICAL

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK LOW LOW NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
CHANGED HIGH HIGH HIGH

CVE References

Description Tags Link
HackerOne hackerone.com
text/html
URL Logo MISC hackerone.com/reports/1672388
2022/CVE-2022-2884.json · master · GitLab.org / cves · GitLab gitlab.com
text/html
URL Logo CONFIRM gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2884.json
RCE via github import (#371098) · Issues · GitLab.org / GitLab · GitLab gitlab.com
text/html
URL Logo MISC gitlab.com/gitlab-org/gitlab/-/issues/371098

Related QID Numbers

  • 376864 GitLab Remote Command Execution Vulnerability
  • 690925 Free Berkeley Software Distribution (FreeBSD) Security Update for gitlab (8a0cd618-22a0-11ed-b1e7-001b217b3468)

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationGitlabGitlabAllAllAllAll
ApplicationGitlabGitlabAllAllAllAll
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*:
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*:

Discovery Credit

Thanks [yvvdwf](https://hackerone.com/yvvdwf) for reporting this vulnerability through our HackerOne bug bounty program.

Social Mentions

Source Title Posted (UTC)
Twitter Icon @sidfm_jp GitLab の Github インポートの処理に任意のコードを実行される問題 (CVE-2022-2884) [43142] sid.softek.jp/content/show/4… #SIDfm #脆弱性情報 2022-08-23 06:00:04
Twitter Icon @atluxity CVE-2022-2884 - GitLab CE/EE allows an an authenticated user to achieve remote code execution via the Import from G… twitter.com/i/web/status/1… 2022-08-23 08:29:00
Twitter Icon @the_yellow_fall CVE-2022-2884: GitLab Remote Code Execution Vulnerability securityonline.info/cve-2022-2884-… #opensource #infosec #security #pentesting 2022-08-23 12:27:05
Twitter Icon @AcooEdi CVE-2022-2884: GitLab Remote Command Execution Vulnerability dlvr.it/SX5g2f via securityonline https://t.co/Pb49iQwDju 2022-08-23 12:31:04
Twitter Icon @Komodosec #Vulnerability #CVE20222884 CVE-2022-2884: GitLab Remote Command Execution Vulnerability securityonline.info/cve-2022-2884-… 2022-08-23 13:06:04
Twitter Icon @lucianot54 "CVE-2022-2884: GitLab Remote Command Execution Vulnerability" via Penetration Testing ift.tt/FMsBK4g 2022-08-23 13:23:02
Twitter Icon @moton CVE-2022-2884: GitLab Remote Command Execution Vulnerability - securityonline.info/cve-2022-2884-… 2022-08-23 13:38:40
Twitter Icon @Har_sia CVE-2022-2884 har-sia.info/CVE-2022-2884.… #HarsiaInfo 2022-08-24 07:01:08
Twitter Icon @PentestingN CVE-2022-2884: GitLab Remote Command Execution Vulnerability securityonline.info/cve-2022-2884-… Penetration Testing CVE-2022… twitter.com/i/web/status/1… 2022-08-24 07:14:00
Twitter Icon @EchelonEyes GitLab исправляет критическую уязвимость выполнения произвольного кода. CVE-2022-2884 (оценка CVSS: 9,9) затрагивае… twitter.com/i/web/status/1… 2022-08-24 07:20:35
Twitter Icon @shah_sheikh Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884): GitLab has fixed a remote code execution vulnerab… twitter.com/i/web/status/1… 2022-08-24 10:41:35
Twitter Icon @evanderburg Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) i.securitythinkingcap.com/SX8X3W https://t.co/UxgejYN5ju 2022-08-24 10:41:37
Twitter Icon @helpnetsecurity Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) - helpnetsecurity.com/2022/08/24/cve… - @gitlab #GitLab… twitter.com/i/web/status/1… 2022-08-24 10:43:07
Twitter Icon @PoseidonTPA Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) news.poseidon-us.com/SX8Ysv #PoseidonTPA… twitter.com/i/web/status/1… 2022-08-24 10:57:34
Twitter Icon @cipherstorm Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884): GitLab has fixed a remote code execution vulnerab… twitter.com/i/web/status/1… 2022-08-24 11:02:14
Twitter Icon @DeepFriedCyber Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) dlvr.it/SX8dKl #news #cybersecurity… twitter.com/i/web/status/1… 2022-08-24 11:19:04
Twitter Icon @BibsTech Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) bibstech.live/critical-rce-b… 2022-08-24 11:29:00
Twitter Icon @IT_securitynews Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) itsecuritynews.info/critical-rce-b… 2022-08-24 11:36:20
Twitter Icon @netsecu helpnetsecurity.com/2022/08/24/cve… Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) #cybersecurity 2022-08-24 11:41:05
Twitter Icon @Xc0resecurity Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) dlvr.it/SX8hyw 2022-08-24 11:46:08
Twitter Icon @blu3cloak Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) helpnetsecurity.com/2022/08/24/cve… 2022-08-24 11:51:07
Twitter Icon @OSINT_info helpnetsecurity.com/2022/08/24/cve… Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) #cybersecurity 2022-08-24 11:54:33
Twitter Icon @SecurityNewsbot #Critical RCE bug in GitLab patched, #update ASAP! (CVE-2022-2884) helpnetsecurity.com/2022/08/24/cve… #HelpNetSecurity 2022-08-24 12:00:12
Twitter Icon @MASA89434701 ギットラボのRCEか helpnetsecurity.com/2022/08/24/cve… 2022-08-24 12:17:15
Twitter Icon @CSAsingapore GitLab has released a security update to address a critical vulnerability (CVE-2022-2884) in its Community Edition… twitter.com/i/web/status/1… 2022-08-24 12:23:16
Twitter Icon @SG_Alerts [Notice-CSA] GitLab has released a security update to address a critical vulnerability (CVE-2022-2884) in its Commu… twitter.com/i/web/status/1… 2022-08-24 12:24:32
Twitter Icon @joviannfeed Help Net Security | "Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884)" bit.ly/3POc4RI 2022-08-24 12:28:41
Twitter Icon @hutaro_neko CVE-2022-2884: GitLab Remote Command Execution Vulnerability securityonline.info/cve-2022-2884-… 2022-08-24 12:38:22
Twitter Icon @CVEtrends Top 3 trending CVEs on Twitter Past 24 hrs: CVE-2022-2884: 184.7K (audience size) CVE-2022-2200: 157.7K CVE-2019-1… twitter.com/i/web/status/1… 2022-08-24 13:00:03
Twitter Icon @cyberreport_io Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) - Help Net Security dlvr.it/SX92qctwitter.com/i/web/status/1… 2022-08-24 13:47:03
Twitter Icon @moton Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) - Help Net Security - helpnetsecurity.com/2022/08/24/cve… 2022-08-24 14:19:23
Twitter Icon @Har_sia CVE-2022-2884 har-sia.info/CVE-2022-2884.… #HarsiaInfo 2022-08-24 15:00:08
Twitter Icon @Sec_Cyber Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) securecybersolution.com/critical-rce-b… 2022-08-24 15:00:14
Twitter Icon @TheCyberSecHub Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) helpnetsecurity.com/2022/08/24/cve… 2022-08-24 15:06:59
Twitter Icon @web4x4_es Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) #ciberseguridad #cibersecurity helpnetsecurity.com/2022/08/24/cve… 2022-08-24 15:13:12
Twitter Icon @lgomezperu @helpnetsecurity Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) @gitlab #GitLab #SecurityUpdate… twitter.com/i/web/status/1… 2022-08-24 17:40:20
Twitter Icon @cyberkendra GitLab Patch Critical RCE Flaws (CVE-2022-2884) CVSS: 9.9/10 bug.cyberkendra.com/2022/08/24/git… #security #GitLab 2022-08-24 20:18:35
Twitter Icon @juananvicent RCE En GitLab ?? securityonline.info/cve-2022-2884-… 2022-08-24 20:50:34
Twitter Icon @Secnewsbytes Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) - Help Net Security helpnetsecurity.com/2022/08/24/cve… 2022-08-25 00:36:30
Twitter Icon @lo48576 CVE - CVE-2022-2884 2022-08-25 05:42:56
Twitter Icon @w4yh CVE-2022-2884 / CVSS v3 Base 9.9 // GitLab Critical Security Release: 15.3.1, 15.2.3, 15.1.5 | GitLab about.gitlab.com/releases/2022/… 2022-08-25 07:40:31
Twitter Icon @tony_cleal helpnetsecurity.com/2022/08/24/cve… 2022-08-25 08:18:15
Twitter Icon @MachinaRecord ?GitLabの重大なRCEバグのパッチがリリース:CVE-2022-2884 ?IBM、MQの深刻な脆弱性を修正:CVE-2022-27780、CVE-2022-30115 ⚠️Googleのソフトウェアアップデート装う新た… twitter.com/i/web/status/1… 2022-08-25 09:10:21
Twitter Icon @Har_sia CVE-2022-2884 har-sia.info/CVE-2022-2884.… #HarsiaInfo 2022-08-25 15:02:08
Twitter Icon @qualys #Qualys Threat Protection - GitLab Patches Critical Remote Command Execution Vulnerability (CVE-2022-2884)… twitter.com/i/web/status/1… 2022-08-25 15:56:45
Twitter Icon @pati_gallardo RCE in GitLab installations via the Import from GitHub API endpoint (CVE-2022-2884) bleepingcomputer.com/news/security/… 2022-08-25 17:32:21
Twitter Icon @KrollWire We are tracking CVE-2022-2884, a critical vulnerability affecting #GitLab, that allows an authenticated attacker to… twitter.com/i/web/status/1… 2022-08-25 18:10:02
Twitter Icon @CyberSecDN Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) securecybersolution.com/critical-rce-b… #Sec_Cyber 2022-08-26 08:01:13
Twitter Icon @TheSecMaster1 In this post, let’s see the summary, versions affected, and finally how to fix CVE-2022-2884, a critical authentica… twitter.com/i/web/status/1… 2022-08-26 15:30:18
Twitter Icon @_Vault_Security Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884). helpnetsecurity.com/2022/08/24/cve… #infosec #cybersec #cybersecurity #RCE #gitlab 2022-08-27 02:30:00
Twitter Icon @RedPacketSec GitLab command execution | CVE-2022-2884 - redpacketsecurity.com/gitlab-command… #CVE #Vulnerability #OSINT #ThreatIntel #Cyber 2022-08-27 09:01:57
Twitter Icon @graph_inc اطلاعیه رسمی GitLab برای رفع یک آسیب‌پذیری حیاتی (CVE-2022-2884) در نسخه Community (CE) و Enterprise Edition (EE) ب… twitter.com/i/web/status/1… 2022-08-28 10:31:09
Twitter Icon @d0znpp #gitlab RCE is critical CVE-2022-2884. Urgent Update Required #apisecurity #injections lnkd.in/gzQN3wDQ It… twitter.com/i/web/status/1… 2022-08-28 15:07:44
Twitter Icon @FrankMarano6 [email protected] is tracking CVE-2022-2884, a critical vulnerability affecting GitLab, allowing an authenticated attacke… twitter.com/i/web/status/1… 2022-08-30 16:07:44
Twitter Icon @hasdid #HelpNetSecurity #CyberSecurity #Automated | Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884) helpnetsecurity.com/2022/08/24/cve… 2022-08-30 18:47:06
Twitter Icon @iototsecnews GitLab の深刻な脆弱性 CVE-2022-2884 が FIX:認証済みの攻撃者による RCE #security #vulnerability #gitlab iototsecnews.jp/2022/08/23/git… 2022-08-30 22:18:05
Twitter Icon @LouisMuniz10 [email protected] is tracking CVE-2022-2884, a critical vulnerability affecting GitLab, allowing an authenticated attacke… twitter.com/i/web/status/1… 2022-08-31 16:03:41
Twitter Icon @CycodeHQ GitLab issued patches for a critical RCE vulnerability (CVE-2022-2884), impacting both Community and Enterprise edi… twitter.com/i/web/status/1… 2022-09-06 14:00:01
Twitter Icon @eb_compliance [email protected] is tracking CVE-2022-2884, a critical vulnerability affecting GitLab, allowing an authenticated attacke… twitter.com/i/web/status/1… 2022-09-07 17:17:15
Twitter Icon @goprivacy1 Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884): GitLab has… dlvr.it/SY5tkr @RedSeal_co… twitter.com/i/web/status/1… 2022-09-10 17:43:34
Twitter Icon @CycodeHQ GitLab issued patches for a critical RCE vulnerability (CVE-2022-2884), impacting both Community and Enterprise edi… twitter.com/i/web/status/1… 2022-09-21 18:30:00
Twitter Icon @CVEreport CVE-2022-2884 : A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3,… twitter.com/i/web/status/1… 2022-10-17 16:14:57
Reddit Logo Icon /r/gitlab CVE-2022-2884 (9.9/10), beware if you're using certificate-based integration with Kubernetes 2022-08-23 07:20:27
Reddit Logo Icon /r/KomodoCyberConsulting CVE-2022-2884: GitLab Remote Command Execution Vulnerability 2022-08-23 13:06:05
Reddit Logo Icon /r/programming DevOps platform GitLab has released security updates to fix a critical remote code execution vulnerability, tracked as CVE-2022-2884 (CVSS 9.9), affecting its GitLab Community Edition (CE) and Enterprise Edition (EE) releases. 2022-08-24 02:58:59
Reddit Logo Icon /r/netcve CVE-2022-2884 2022-10-17 17:38:42
© CVE.report 2023 Twitter Nitter Twitter Viewer |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report