CVE-2022-1162 is a critical vulnerability in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2, where a hardcoded password ('123qweQWE!@#000000000') was set for accounts registered using OmniAuth providers (OAuth, LDAP, SAML). This flaw allows attackers to authenticate as any affected user by using the hardcoded password, leading to potential account takeover. The vulnerability is categorized under CWE-798 (Use of Hard-coded Credentials) and affects both community and enterprise editions of GitLab.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python exploit script (code.py) and a README.md for CVE-2022-1162, a vulnerability in GitLab. The exploit automates the process of enumerating users from GitLab projects and attempts to log in to each user account using a hardcoded default password ('123qweQWE!@#000000000'). The script interacts with the GitLab web interface by sending HTTP requests to endpoints such as '/explore', '/-/project_members', and '/users/sign_in'. It parses HTML responses to extract user information and attempts authentication, reporting successful logins. The README provides usage instructions and an example command. The exploit is operational, requiring a vulnerable GitLab instance accessible over the network. No fake or destructive code is present; the script is focused on exploiting the specific CVE for account takeover.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.