CVE-2022-3767
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
Affected (1)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.11.0 to 3.0.32 |
References (4)
Source: cve@gitlab.com
Vendor Advisory
Source: cve@gitlab.com
ExploitIssue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchVendor Advisory
Timeline
No history available yet.