CVE-2022-2884: OS Command Injection
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2884?
CVE-2022-2884 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2022-2884?
To fix CVE-2022-2884, upgrade GitLab to version 15.1.5 or later, or apply any available patches.
What versions are affected by CVE-2022-2884?
CVE-2022-2884 affects all versions of GitLab from 11.3.4 prior to 15.1.5, as well as 15.2 to 15.2.3 and 15.3 to 15.3.1.
What does CVE-2022-2884 allow an attacker to do?
CVE-2022-2884 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.
Is CVE-2022-2884 related to GitHub integration in GitLab?
Yes, CVE-2022-2884 specifically relates to the GitHub integration feature within GitLab.