MEDIUM

CVE-2022-4315

Gitlab Dynamic Application Security Testing Analyzer 2023-03-08 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

0.81%
Probability of exploitation in next 30 days
55.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE