This website uses cookies essential to its operation, for analytics, and for personalized content. By continuing to browse this site, you acknowledge the use of cookies. For details on cookie usage on our site, read our Privacy Policy
Hi Lychiang ,
May I know if this is the remediation/workaround for the abovementioned CVEs?
I checked Palo Alto advisories as well but there is no mention of this as this is still an ongoing investigation.
Also, what about these CVEs?
- CVE-2022-4203 - CVE-2023-0216 - CVE-2023-0217 - CVE-2023-0401
... View more
Hi,
Does anyone know if GitLab Remote Command Execution Vulnerability is covered with Palo Alto AV Signature?
Is Palo Alto affected by it?
I was not able to find it in their Security Advisories.
Vulnerability Details:
Title
GitLab Remote Command Execution Vulnerability
CVE ID
CVE-2022-2884
CVE Summary
GitLab Community Edition and GitLab Enterprise Edition are prone to remote code-execution vulnerabilities via GitHub Import. An attacker can leverage this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial of service conditions.
The vulnerability has a CVSS base score of 9.9.
Link(s)
https://about.gitlab.com/releases/2022/08/22/critical-security-release-gitlab-15-3-1-released/
Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.
... View more