Critical severity9.9NVD Advisory· Published Oct 17, 2022· Updated Jun 17, 2026
CVE-2022-2992
CVE-2022-2992
Description
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=11.10,<15.1.6
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=11.10,<15.1.6
- (no CPE)range: >=11.10, <15.1.6
- Range: 11.10 to <15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2
Patches
Vulnerability mechanics
References
4- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2992.jsonnvdThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/371884nvdBroken LinkThird Party Advisory
- hackerone.com/reports/1679624nvdPermissions RequiredThird Party Advisory
- packetstormsecurity.com/files/171008/GitLab-GitHub-Repo-Import-Deserialization-Remote-Code-Execution.htmlnvd
News mentions
0No linked articles in our index yet.