Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[add-request] CVE-2022-2884 - GitLab Remote Command Execution via Github import #27

Open
p0dalirius opened this issue Aug 24, 2022 · 0 comments
Assignees
Labels
add-request Request a new RCE technique other

Comments

@p0dalirius
Copy link
Owner

A vulnerability in GitLab CE/EE affecting all versions starting from 11.3.4 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint. This is a Critical severity issue (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, 9.9). It is now mitigated in the latest release and is assigned CVE-2022-2884.

https://about.gitlab.com/releases/2022/08/22/critical-security-release-gitlab-15-3-1-released/

@p0dalirius p0dalirius added add-request Request a new RCE technique other labels Aug 24, 2022
@p0dalirius p0dalirius self-assigned this Aug 24, 2022
@p0dalirius p0dalirius changed the title [enhancement] CVE-2022-2884 - GitLab Remote Command Execution via Github import [add-request] CVE-2022-2884 - GitLab Remote Command Execution via Github import Aug 24, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
add-request Request a new RCE technique other
Projects
None yet
Development

No branches or pull requests

1 participant