VDB
GCVE-110-CLOUD-2022-0017
GCVE-110-CLOUD-2022-0017
Advisory Published
A critical vulnerability in GitLab's GitHub import feature allows remote code execution. The issue stems from improper handling of Sawyer::Resource objects, enabling injection of Redis commands. This can be escalated to execute arbitrary bash commands on the SaaS managed service as well as self-hosted GitLab servers, potentially leading to full system compromise.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| GitHub | GitLab Import | — | — |
| GitHub | Cloud Services | — | — |
Browse GCVE Records
74,267 records in the GCVE database · Updated July 22, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.