Exploitation Summary
EIP tracks 2 public exploits for CVE-2022-2884. PoCs published by Antonio Francesco Sardella, m3ssap0.
AI-analyzed exploit summary This Python script exploits CVE-2022-2884, an authenticated RCE vulnerability in GitLab via the Import from GitHub API endpoint. It sets up a fake GitHub server to intercept and execute arbitrary commands on the target GitLab instance.
Description
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint
Exploits (2)
This Python script exploits CVE-2022-2884, an authenticated RCE vulnerability in GitLab via the Import from GitHub API endpoint. It sets up a fake GitHub server to intercept and execute arbitrary commands on the target GitLab instance.
This repository contains a Python3 exploit for CVE-2022-2884, an authenticated RCE vulnerability in GitLab CE/EE versions prior to 15.1.5, 15.2.3, and 15.3.1. The exploit leverages the Import from GitHub API endpoint to achieve remote code execution.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H