logo

GitLab Password Security Vulnerability CVE-2022-1162

ID: 282f194e-d481-535a-9d40-ecabc59b3cc1

STIX ID: report--282f194e-d481-535a-9d40-ecabc59b3cc1

Feed Name: Arctic Wolf Blog

Threat Score
70/100

Date Published: 2022-04-03

Date Updated: 2026-04-26

...
...

GitLab released an advisory for CVE-2022-1162, a critical vulnerability in GitLab CE/EE where accounts created via OmniAuth (OAuth, LDAP, SAML) could be assigned predictable hard-coded passwords that attackers could brute-force. Affected GitLab versions include 14.7.x through 14.9.1 with fixed releases available (14.7.7, 14.8.5, 14.9.2). The report recommends patching vulnerable instances immediately, using GitLab's provided script to identify impacted users on self-managed instances, and resetting affected user passwords.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.