GitLab Password Security Vulnerability CVE-2022-1162
ID: 282f194e-d481-535a-9d40-ecabc59b3cc1
STIX ID: report--282f194e-d481-535a-9d40-ecabc59b3cc1
Feed Name: Arctic Wolf Blog
GitLab released an advisory for CVE-2022-1162, a critical vulnerability in GitLab CE/EE where accounts created via OmniAuth (OAuth, LDAP, SAML) could be assigned predictable hard-coded passwords that attackers could brute-force. Affected GitLab versions include 14.7.x through 14.9.1 with fixed releases available (14.7.7, 14.8.5, 14.9.2). The report recommends patching vulnerable instances immediately, using GitLab's provided script to identify impacted users on self-managed instances, and resetting affected user passwords.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
