Critical severity9.9NVD Advisory· Published Oct 17, 2022· Updated Jun 17, 2026
CVE-2022-2884
CVE-2022-2884
Description
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: 11.3.4 to <15.1.5, 15.2 to 15.2.3, 15.3 to 15.3.1
- Range: >=11.3.4, <15.1.5
Patches
Vulnerability mechanics
References
4- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2884.jsonnvdThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/371098nvdThird Party Advisory
- hackerone.com/reports/1672388nvdPermissions RequiredThird Party Advisory
- packetstormsecurity.com/files/171628/GitLab-15.3-Remote-Code-Execution.htmlnvd
News mentions
0No linked articles in our index yet.