MEDIUM

CVE-2022-3767

Gitlab Dynamic Application Security Testing Analyzer 2023-03-09 CVSS v3.1
CVSS
6.5

Description

Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.

Weakness (CWE)

CWE-20 Improper Input Validation

EPSS Score

0.75%
Probability of exploitation in next 30 days
53.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE