CVE-2022-1162
Gitlab 14.9 - Authentication Bypass
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts
En GitLab CE/EE versiones 14.7 anteriores a 14.7.7, 14.8 anteriores a 14.8.5 y 14.9 anteriores a 14.9.2, era establecida una contraseƱa embebida para las cuentas registradas mediante un proveedor de OmniAuth (por ejemplo, OAuth, LDAP, SAML), permitiendo a atacantes tomar el control de las cuentas
Gitlab versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.7 prior to 14.7.7 suffer from a bypass vulnerability due to having set a hardcoded password for accounts registered using an OmniAuth provider.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-29 CVE Reserved
- 2022-04-04 CVE Published
- 2022-04-12 First Exploit
- 2024-08-02 CVE Updated
- 2024-11-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-798: Use of Hard-coded Credentials
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/166828/Gitlab-14.9-Authentication-Bypass.html | Third Party Advisory | |
https://gitlab.com/gitlab-org/gitlab/-/issues/357210 | Broken Link |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/50888 | 2022-04-26 | |
https://github.com/Greenwolf/CVE-2022-1162 | 2022-04-12 | |
https://github.com/ipsBruno/CVE-2022-1162 | 2022-11-09 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1162.json | 2022-04-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 14.7.0 < 14.7.7 Search vendor "Gitlab" for product "Gitlab" and version " >= 14.7.0 < 14.7.7" | community |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 14.7.0 < 14.7.7 Search vendor "Gitlab" for product "Gitlab" and version " >= 14.7.0 < 14.7.7" | enterprise |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 14.8.0 < 14.8.5 Search vendor "Gitlab" for product "Gitlab" and version " >= 14.8.0 < 14.8.5" | community |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 14.8.0 < 14.8.5 Search vendor "Gitlab" for product "Gitlab" and version " >= 14.8.0 < 14.8.5" | enterprise |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 14.9.0 < 14.9.2 Search vendor "Gitlab" for product "Gitlab" and version " >= 14.9.0 < 14.9.2" | community |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 14.9.0 < 14.9.2 Search vendor "Gitlab" for product "Gitlab" and version " >= 14.9.0 < 14.9.2" | enterprise |
Affected
|