Vulnerability record · CVE-2022-2992 · published 17 October 2022
CVE-2022-2992: GitLab GitHub import endpoint deserialization leads to remote code execution
Gitlab · Gitlab
GitLab CE/EE versions from 11.10 before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 contain an injection flaw in the Import from GitHub API endpoint. An authenticated user can trigger remote code execution through that endpoint, and the CVSS 3.1 score is 9.9 (critical) with scope change.
Description
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.9 with scope change and remote code execution from an authenticated account, plus a very high EPSS probability, makes this a top remediation priority.
What it is
GitLab CE/EE versions from 11.10 before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 contain an injection flaw in the Import from GitHub API endpoint. An authenticated user can trigger remote code execution through that endpoint, and the CVSS 3.1 score is 9.9 (critical) with scope change.
Impact
An attacker with a valid account gains remote code execution on the GitLab server, which can lead to full compromise of the instance and its data.
Attack surface
Reached over the network through the Import from GitHub API endpoint; the vector shows low privileges required (PR:L) and no user interaction (UI:N), so any authenticated user is sufficient.
Exploitation
Not listed in CISA KEV, but EPSS is very high at 0.86194 (99.7th percentile), and public references include a Packet Storm writeup titled as deserialization remote code execution, indicating public technical detail exists.
What to do
- Upgrade GitLab CE/EE to 15.1.6, 15.2.4, 15.3.2 or later as applicable to your release line.
- If immediate patching is not possible, restrict or disable the Import from GitHub feature and limit who can create projects.
- Review and reduce the number of users with project creation and import permissions.
- Monitor GitLab logs for unexpected GitHub import activity and investigate any server-side process anomalies.
- Apply network controls so the GitLab instance is not directly reachable from untrusted networks where feasible.
Detection
- Alert on GitHub import API requests, especially from accounts or IPs not normally performing imports.
- Look for unexpected child processes or command execution spawned by GitLab Rails/Workhorse components.
- Review GitLab application and system logs for import errors or anomalies around the time of suspected activity.
- Correlate new project creation with subsequent outbound or unusual server activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/171008/GitLab-GitHub-Repo-Import-Deserialization-Remote-Code-Execution.html | |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2992.json | Third Party Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/371884 | Broken LinkThird Party Advisory |
| https://hackerone.com/reports/1679624 | Permissions RequiredThird Party Advisory |
| http://packetstormsecurity.com/files/171008/GitLab-GitHub-Repo-Import-Deserialization-Remote-Code-Execution.html | |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2992.json | Third Party Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/371884 | Broken LinkThird Party Advisory |
| https://hackerone.com/reports/1679624 | Permissions RequiredThird Party Advisory |
Track CVE-2022-2992 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-2992), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.