Upgrade to 14.9.2 due to Critical CVE-2022-1162
GitLab announced a security update today.
Included was a CVE that had a static password set for omniauth-based registration that could lead to malicious account takeover.
- https://about.gitlab.com/releases/2022/03/31/critical-security-release-gitlab-14-9-2-released/#static-passwords-inadvertently-set-during-omniauth-based-registration
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1162
The suggested fix is to upgrade to 14.8.5.
The 14.8.5 fix also deals with a couple high severity and several other CVEs.
Edited by kevin.wilder