CVE-2022-2185
CRITICAL severity · CVSS 9.9 · OS command injection
9.9CVSS CRITICAL
Summary
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)87%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Additional information
- NVD record
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2185.jsonAdvisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2185.jsonAdvisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/366088
- https://hackerone.com/reports/1609965Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/366088
- https://hackerone.com/reports/1609965Advisory