CVE Vulnerabilities

CVE-2022-3767

Published: Mar 09, 2023 | Modified: Mar 15, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.

Affected Software

Name Vendor Start Version End Version
Dynamic_application_security_testing_analyzer Gitlab 1.11.0 (including) 3.0.32 (excluding)

References