Home » Database

AVID-2026-R1012

Description

Vulnerability CVE-2022-2884

Details

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

Reason for inclusion in AVID: CVE-2022-2884 describes a remote code execution vulnerability in GitLab CE/EE. GitLab is widely used in AI development pipelines for CI/CD, model training orchestration, and artifact management. As such, this is a software supply-chain vulnerability affecting components (CI/CD, deployment pipelines) used to build, package, deploy, or run AI systems. It is clearly a security vulnerability with high impact, and the report provides explicit CVE details and references.

References

Affected or Relevant Artifacts

  • Developer: GitLab
  • Deployer: GitLab
  • Artifact Details:
TypeName
SystemGitLab

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Base Score9.9
Base Severity🔴 Critical
Attack VectorNETWORK
Attack Complexity🟢 Low
Privileges Required🟢 Low
User InteractionNONE
ScopeCHANGED
Confidentiality Impact🔴 High
Integrity Impact🔴 High
Availability Impact🔴 High

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2022-10-17
  • Version: 0.3.3
  • AVID Entry