🔙 목록으로 돌아가기

CVE-2022-2185: GitLab CE/EE - Remote Code Execution

TitleGitLab CE/EE - Remote Code Execution
AuthorGitLab Red Team
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationApply the latest security patches provided by GitLab to mitigate this vulnerability.
CVSS Score8.8
EPSS Score0.93208
CVE IDCVE-2022-2185
CWE IDCWE-78
Shodan Queryhttp.title:"GitLab"cpe:"cpe:2.3:a:gitlab:gitlab"http.title:"gitlab"
Fofa Querytitle="gitlab"
Tags cve cve2022 gitlab vuln

🔍 Vulnerability Description

GitLab CE/EE 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 is susceptible to remote code execution. An authenticated user authorized to import projects can import a maliciously crafted project, thus possibly being able to execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.

🌐 HTTP Request

GET /users/sign_in HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.6.14
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-2185.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-2185.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A