Vulnerability record · CVE-2022-2884 · published 17 October 2022
CVE-2022-2884: GitLab GitHub import API command injection enables remote code execution
Gitlab · Gitlab
GitLab CE/EE contains an OS command injection flaw (CWE-78) in the Import from GitHub API endpoint. An authenticated user can leverage it to execute arbitrary commands on the server, and the affected range spans versions from 11.3.4 up to before 15.1.5, plus 15.2 through 15.2.3 and 15.3 through 15.3.1. With a CVSS 3.1 score of 9.9 and a scope-changing vector, this is a severe issue for any exposed GitLab instance.
Description
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.9 with scope change, authenticated remote code execution, and very high EPSS make this an urgent patch target despite no KEV listing.
What it is
GitLab CE/EE contains an OS command injection flaw (CWE-78) in the Import from GitHub API endpoint. An authenticated user can leverage it to execute arbitrary commands on the server, and the affected range spans versions from 11.3.4 up to before 15.1.5, plus 15.2 through 15.2.3 and 15.3 through 15.3.1. With a CVSS 3.1 score of 9.9 and a scope-changing vector, this is a severe issue for any exposed GitLab instance.
Impact
An attacker with a valid account gains remote code execution on the GitLab host, which can lead to full compromise of the application and its data. Because the CVSS scope is changed, impact can extend beyond the vulnerable component to the underlying system.
Attack surface
The flaw is reached over the network through the Import from GitHub API endpoint. It requires authentication (PR:L) but no user interaction (UI:N), so any low-privileged account is sufficient to attempt exploitation.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at roughly 0.757 (99.5th percentile), and public references include a Packet Storm write-up and a HackerOne report, indicating exploit knowledge is publicly available. No ransomware group usage is documented in the record.
What to do
- Upgrade GitLab CE/EE to 15.1.5, 15.2.4, 15.3.2 or later, which are the fixed releases for the affected ranges.
- If immediate upgrade is not possible, restrict or disable the Import from GitHub feature and limit API access to trusted users.
- Audit and reduce the number of authenticated accounts, and enforce least privilege so low-privileged users cannot reach import functionality.
- Monitor GitLab server logs and process activity for unexpected command execution originating from the import endpoint.
- Apply network controls so GitLab is not directly reachable from untrusted networks where possible.
Detection
- Review GitLab production logs for Import from GitHub API requests, especially from accounts that do not normally use imports.
- Hunt for anomalous child processes spawned by the GitLab web/worker processes, such as shells or unexpected binaries.
- Alert on outbound network connections from the GitLab host to unfamiliar destinations following import activity.
- Correlate authentication events with import endpoint access to identify low-privileged accounts triggering the feature.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/171628/GitLab-15.3-Remote-Code-Execution.html | |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2884.json | Third Party Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/371098 | Third Party Advisory |
| https://hackerone.com/reports/1672388 | Permissions RequiredThird Party Advisory |
| http://packetstormsecurity.com/files/171628/GitLab-15.3-Remote-Code-Execution.html | |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2884.json | Third Party Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/371098 | Third Party Advisory |
| https://hackerone.com/reports/1672388 | Permissions RequiredThird Party Advisory |
Track CVE-2022-2884 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-2884), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.