CRITICAL

CVE-2022-1162

CVSS v3

9.8

CRITICAL

EPSS Score

89.7%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

Technical details

Published
4/4/2022
Exploit-DB
EDB-50888

Frequently asked questions

What is CVE-2022-1162?

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

Is CVE-2022-1162 actively exploited?

Active exploitation of CVE-2022-1162 has not been confirmed. The EPSS score is 89.7%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-1162?

CVE-2022-1162 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2022-1162 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.