CVE-2022-3767

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/03/2023
Last modified:
28/02/2025

Description

Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:dynamic_application_security_testing_analyzer:*:*:*:*:*:*:*:* 1.11.0 (including) 3.0.32 (excluding)