VDB

GCVE-110-CLOUD-2022-0017

GCVE-110-CLOUD-2022-0017
Advisory Published
Vulnetix · Advisory published August 17, 2022
A critical vulnerability in GitLab's GitHub import feature allows remote code execution. The issue stems from improper handling of Sawyer::Resource objects, enabling injection of Redis commands. This can be escalated to execute arbitrary bash commands on the SaaS managed service as well as self-hosted GitLab servers, potentially leading to full system compromise.

Affected Products

VendorProductVersionsPlatforms
GitHubGitLab Import
GitHubCloud Services

References

advisory
advisory

Browse GCVE Records

74,267 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›