CVE-2022-2498
Status: ModifiedHigh (7.5)—
An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.84%
- Percentile among all scored CVEs: 57
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-269
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2498.json
- https://gitlab.com/gitlab-org/gitlab/-/issues/243703
- https://hackerone.com/reports/966824
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2498.json
- https://gitlab.com/gitlab-org/gitlab/-/issues/243703
- https://hackerone.com/reports/966824
Raw JSON (NVD)
Show
{
"id": "CVE-2022-2498",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve@gitlab.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@gitlab.com",
"affectedData": [
{
"vendor": "GitLab",
"product": "GitLab",
"versions": [
{
"status": "affected",
"version": ">=12.8, <15.0.5"
},
{
"status": "affected",
"version": ">=15.1, <15.1.4"
},
{
"status": "affected",
"version": ">=15.2, <15.2.1"
}
]
}
]
}
],
"published": "2022-08-05T16:15:12.137",
"references": [
{
"url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2498.json",
"tags": [
"Vendor Advisory"
],
"source": "cve@gitlab.com"
},
{
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/243703",
"tags": [
"Broken Link",
"Vendor Advisory"
],
"source": "cve@gitlab.com"
},
{
"url": "https://hackerone.com/reports/966824",
"tags": [
"Permissions Required",
"Third Party Advisory"
],
"source": "cve@gitlab.com"
},
{
"url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2498.json",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/243703",
"tags": [
"Broken Link",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://hackerone.com/reports/966824",
"tags": [
"Permissions Required",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author."
},
{
"lang": "es",
"value": "Un problema en las suscripciones a pipelines en GitLab EE afectando a todas las versiones desde la 12.8 anteriores a 15.0.5, la 15.1 anteriores a 15.1.4 y la 15.2 anteriores a 15.2.1, desencadena nuevos pipelines con la persona que creó la etiqueta como creador de tubería en lugar del autor de la suscripción"
}
],
"lastModified": "2026-06-17T04:42:00.470",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2803CE66-92D2-41EF-9CB1-FCB133732CF6",
"versionEndExcluding": "15.0.5",
"versionStartIncluding": "12.8.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B835154E-74C9-40CC-9CB1-D0644E8FB5AB",
"versionEndExcluding": "15.1.4",
"versionStartIncluding": "15.1.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4ECA8C34-F6D0-4ED7-8278-041D709296BC"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@gitlab.com"
}