CVE-2022-1162

Description from NVD

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

Information Acquisition Date:2022-04-30T16:40Z
CVSS 2.0: 7.5 HIGH CVSS 3.x: 9.8 CRITICAL

▼ CVSS3 Vec CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

▼ CVSS2 Vec AV:N/AC:L/Au:N/C:P/I:P/A:P

NVD References

 https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1162.json
     source:CONFIRM
     tags:Vendor Advisory    
 https://gitlab.com/gitlab-org/gitlab/-/issues/357210
     source:MISC
     tags:Broken Link    
 http://packetstormsecurity.com/files/166828/Gitlab-14.9-Authentication-Bypass.html
     source:MISC
     tags:Third Party Advisory    VDB Entry    

Refer to Information on External Sites

CVE InfomationExploits or more Infomation
mitreEXPLOIT DATABASE
NVD0day.today
vulmon.comgithub
CVE DetailsTwitter
JVN ENG JPN
Reconshell

Software Tag:



List of frequently cited URLs

URLNum of Times Referred to
https://cvetrends.com54
http://twinybots.ch33
https://thehackernews.com/2022/04/gitlab-releases-patch-for...10
https://opsmtrs.com/2ZFbaTl9
https://securityaffairs.co/wordpress/129730/hacking/cve-202...5
https://www.bleepingcomputer.com/news/security/critical-git...5
https://ift.tt/VDOfqpM4
https://twitter.com/BleepinComputer/status/15099067037892730904
https://securityonline.info/cve-2022-1162-gitlab-vulnerability4
https://about.gitlab.com/releases/2022/03/31/critical-secur...3

Information from Twitter

User URL Info Source Date
VulmonFeeds https://alerts.vulmon.com/?utm_source=twitter&utm_medium=so... Source VulmonFeeds      1640817809998376960 2023/03/29

List of frequently cited URLs

URLNum of Times Referred to
cvetrends.com54
twinybots.ch33
thehackernews.com10
opsmtrs.com9
securityaffairs.co5
www.bleepingcomputer.com5
ift.tt4
twitter.com4
securityonline.info4
about.gitlab.com3

Information from Twitter

User URL Info Source
VulmonFeeds alerts.vulmon.com Show Tweet

GitHub Search Results: Up to 10
NameURL
Greenwolf/CVE-2022-1162 https://github.com/Greenwolf/CVE-2022-1162

GitHub Search Results: Up to 10
NameURL
Greenwolf/CVE-2022-1162 github.com

2023/03/29 Score : 1
Added Har-sia Database : 2022/04/01
Last Modified : 2023/03/29
Highest Scored Date : 2022/04/02
Highest Score : 61