CVE-2022-3767

Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:gitlab:dynamic_application_security_testing_analyzer:*:*:*:*:*:*:*:*

History

15 Mar 2023, 16:41

Type Values Removed Values Added
References (MISC) https://gitlab.com/gitlab-org/gitlab/-/issues/377473 - (MISC) https://gitlab.com/gitlab-org/gitlab/-/issues/377473 - Exploit, Issue Tracking, Patch, Vendor Advisory
References (CONFIRM) https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3767.json - (CONFIRM) https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3767.json - Vendor Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:gitlab:dynamic_application_security_testing_analyzer:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

10 Mar 2023, 13:53

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-09 23:15

Updated : 2024-02-04 23:14


NVD link : CVE-2022-3767

Mitre link : CVE-2022-3767

CVE.ORG link : CVE-2022-3767


JSON object : View

Products Affected

gitlab

  • dynamic_application_security_testing_analyzer