CVE-2022-3767
PoC —CVSS 3.1
6.5 medium
EPSS
<1%p53
Published
()
Modified
Description
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
- Vendors
- gitlab
- Products
- dynamic application security testing analyzer
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.