{"id":"CVE-2022-1162","details":"A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts","aliases":["BIT-gitlab-2022-1162"],"modified":"2026-09-11T03:48:13.951644903Z","published":"2022-04-04T19:46:14Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1162.json","cna_assigner":"GitLab"},"references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/166828/Gitlab-14.9-Authentication-Bypass.html"},{"type":"WEB","url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1162.json"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1162.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-1162"},{"type":"REPORT","url":"https://gitlab.com/gitlab-org/gitlab/-/issues/357210"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/gitlab-org/gitlab","events":[{"introduced":"1fdefb34741e329ede520eba6c3038eb48bfa191"},{"fixed":"3034418fb311e288d880c55ee707d9a3eecfe07d"},{"introduced":"1d7d0b0a1db4c69533330ab29c6c0d3bdb17adba"},{"fixed":"fdf232e4acc50b3f86090b2c18253449577616dc"},{"introduced":"621e59848886e0dceec7a248ce6266450a7b5e21"},{"fixed":"6d5453caf44cbb4379bebe8a406551db5441a5a2"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"14.9"},{"fixed":"14.9.2"},{"introduced":"14.8"},{"fixed":"14.8.5"},{"introduced":"14.7"},{"fixed":"14.7.7"}]}}],"versions":["v14.7.6-ee","v14.9.1-ee","v14.7.5-ee","v14.9.0-ee","v14.8.4-ee","v14.7.3-ee","v14.8.1-ee","v14.8.3-ee","v14.8.0-ee","v14.7.2-ee","v14.7.1-ee","v14.7.0-ee"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1162.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}