CVE-2022-1162: Critical severity gitlab vulnerability
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1162?
CVE-2022-1162 is considered a high severity vulnerability due to the potential for account takeover.
How do I fix CVE-2022-1162?
To fix CVE-2022-1162, upgrade your GitLab instance to version 14.7.7, 14.8.5, or 14.9.2 or later.
Which versions of GitLab are affected by CVE-2022-1162?
CVE-2022-1162 affects GitLab CE/EE versions prior to 14.7.7, 14.8.5, and 14.9.2.
What types of accounts are vulnerable in CVE-2022-1162?
CVE-2022-1162 affects accounts registered using OmniAuth providers such as OAuth, LDAP, or SAML.
Can CVE-2022-1162 lead to data breaches?
Yes, due to the hardcoded password issue in CVE-2022-1162, attackers can potentially gain access to user accounts and sensitive data.