CVE-2022-3767 Information

Description

Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32 allows custom request headers to be sent with every request regardless of the host.

Reference

https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3767.json https://gitlab.com/gitlab-org/gitlab/-/issues/377473

Share on: