CVE-2022-2185
CRITICAL NUCLEIGitLab <14.10.5-15.1.1 - Authenticated RCE
Title source: llmDescription
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution.
Exploits (3)
github
34 stars
by DarkFunct · cpoc
https://github.com/DarkFunct/CVE_Exploits/tree/main/CVE-2022-2185
Nuclei Templates (1)
GitLab CE/EE - Remote Code Execution
HIGHby GitLab Red Team
Shodan:
http.title:"GitLab" || cpe:"cpe:2.3:a:gitlab:gitlab" || http.title:"gitlab"
FOFA:
title="gitlab"
Scores
CVSS v3
9.9
EPSS
0.9011
EPSS Percentile
99.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (2)
gitlab/gitlab
15.1.0 (2 CPE variants)
gitlab/gitlab
14.0.0 - 14.10.5 (2 CPE variants)
Published
Jul 01, 2022
Tracked Since
Feb 18, 2026