Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-1162

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts
Exploit prediction scoring system (EPSS) score
EPSS Score 0.899
EPSS Ranking 99.6%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 7.5
Products affected by CVE-2022-1162
  • Gitlab » Gitlab » Version: 14.7.0
    cpe:2.3:a:gitlab:gitlab:14.7.0
  • Gitlab » Gitlab » Version: 14.7.1
    cpe:2.3:a:gitlab:gitlab:14.7.1
  • Gitlab » Gitlab » Version: 14.7.2
    cpe:2.3:a:gitlab:gitlab:14.7.2
  • Gitlab » Gitlab » Version: 14.7.3
    cpe:2.3:a:gitlab:gitlab:14.7.3
  • Gitlab » Gitlab » Version: 14.7.4
    cpe:2.3:a:gitlab:gitlab:14.7.4
  • Gitlab » Gitlab » Version: 14.7.5
    cpe:2.3:a:gitlab:gitlab:14.7.5
  • Gitlab » Gitlab » Version: 14.7.6
    cpe:2.3:a:gitlab:gitlab:14.7.6
  • Gitlab » Gitlab » Version: 14.8.0
    cpe:2.3:a:gitlab:gitlab:14.8.0
  • Gitlab » Gitlab » Version: 14.8.1
    cpe:2.3:a:gitlab:gitlab:14.8.1
  • Gitlab » Gitlab » Version: 14.8.2
    cpe:2.3:a:gitlab:gitlab:14.8.2
  • Gitlab » Gitlab » Version: 14.8.3
    cpe:2.3:a:gitlab:gitlab:14.8.3
  • Gitlab » Gitlab » Version: 14.8.4
    cpe:2.3:a:gitlab:gitlab:14.8.4
  • Gitlab » Gitlab » Version: 14.9.0
    cpe:2.3:a:gitlab:gitlab:14.9.0
  • Gitlab » Gitlab » Version: 14.9.1
    cpe:2.3:a:gitlab:gitlab:14.9.1


Contact Us

Shodan ® - All rights reserved