QID 376517
Date Published: 2022-04-11
QID 376517: GitLab Static Password Vulnerability For Accounts Registered Using OmniAuth
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE.
Affected versions:
All versions from 14.7 prior to 14.7.7
All versions from 14.8 prior to 14.8.5
All versions from 14.9 prior to 14.9.2
Attackers can take over accounts affected by this vulnerability.
Solution
CVEs related to QID 376517
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Gitlab-Adv |
|
||
| Gitlab-Adv |
|