Vulnerability record · CVE-2022-1162 · published 4 April 2022
CVE-2022-1162: GitLab OmniAuth account takeover via hardcoded password
Gitlab · Gitlab
GitLab CE/EE set a hardcoded password on accounts created through OmniAuth providers such as OAuth, LDAP and SAML. Anyone who knows that static password can authenticate as those accounts, so the flaw undermines the identity guarantees of federated login.
Description
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required and a very high EPSS percentile makes this an urgent account takeover risk.
What it is
GitLab CE/EE set a hardcoded password on accounts created through OmniAuth providers such as OAuth, LDAP and SAML. Anyone who knows that static password can authenticate as those accounts, so the flaw undermines the identity guarantees of federated login.
Impact
An unauthenticated attacker who knows the hardcoded password can log in as any account provisioned via OmniAuth and take it over, gaining that user's repository and API access.
Attack surface
Reachable over the network through the normal GitLab web login with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not state whether the attacker must first know a valid username.
Exploitation
Not listed in CISA KEV, but EPSS is 0.76177 (99.51st percentile), indicating very high predicted exploitation activity; references are vendor and third-party advisories, with no public exploit tag.
What to do
- Upgrade GitLab CE/EE to 14.7.7, 14.8.5, 14.9.2 or later as listed in the vendor advisory.
- After patching, rotate credentials and reset passwords for all accounts created through OmniAuth providers.
- Audit OmniAuth-provisioned accounts for unexpected logins or sessions and revoke active sessions.
- Restrict network exposure of GitLab and enforce MFA where supported to limit password-only login.
Detection
- Review GitLab authentication logs for successful logins to OmniAuth-provisioned accounts from unfamiliar IPs or user agents.
- Alert on password-based logins for accounts that should only authenticate through SSO/SAML/LDAP.
- Hunt for new sessions, API tokens or SSH keys created shortly after logins to those accounts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/166828/Gitlab-14.9-Authentication-Bypass.html | Third Party AdvisoryVDB Entry |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1162.json | Vendor Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/357210 | Broken Link |
| http://packetstormsecurity.com/files/166828/Gitlab-14.9-Authentication-Bypass.html | Third Party AdvisoryVDB Entry |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1162.json | Vendor Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/357210 | Broken Link |
Track CVE-2022-1162 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-1162), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.