PT-2022-2064 · Gitlab · Gitlab Ce/Ee+1
Published
2022-04-01
·
Updated
2024-03-06
·
CVE-2022-1162
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
GitLab CE/EE versions 14.7 prior to 14.7.7
GitLab CE/EE versions 14.8 prior to 14.8.5
GitLab CE/EE versions 14.9 prior to 14.9.2
Description
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab, allowing attackers to potentially take over accounts. The issue is related to the use of hardcoded passwords for accounts registered with OmniAuth providers.
Recommendations
For GitLab CE/EE versions 14.7 prior to 14.7.7, update to version 14.7.7 or later.
For GitLab CE/EE versions 14.8 prior to 14.8.5, update to version 14.8.5 or later.
For GitLab CE/EE versions 14.9 prior to 14.9.2, update to version 14.9.2 or later.
As a temporary workaround, consider restricting access to accounts registered with OmniAuth providers until the update is applied.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitlab
Gitlab Ce/Ee