CVE-2022-3767
published 2023-03-09CVE-2022-3767: Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless…
PriorityP337medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.75%
50.6th percentile
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gitlab | < gitlab 15.10.8+ds1-2 (sid) | gitlab 15.10.8+ds1-2 (sid) |
| gitlab | dast | — | — |
| gitlab | dynamic_application_security_testing_analyzer | >= 1.11.0 < 3.0.32 | 3.0.32 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_redhat7.8HIGH
vendor_debian7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2022-3767: gitlab - Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to ...
vendor_debian·2022·CVSS 7.7
CVE-2022-3767 [HIGH] CVE-2022-3767: gitlab - Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to ...
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
Scope: local
sid: resolved (fixed in 15.10.8+ds1-2)
GHSA
GHSA-5xvv-4r9w-mw22: Missing validation in DAST analyzer affecting all versions from 1
ghsa_unreviewed·2023-03-10
CVE-2022-3767 [MEDIUM] CWE-20 GHSA-5xvv-4r9w-mw22: Missing validation in DAST analyzer affecting all versions from 1
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
OSV
CVE-2022-3767: Missing validation in DAST analyzer affecting all versions from 1
osv·2023-03-09·CVSS 6.5
CVE-2022-3767 [MEDIUM] CVE-2022-3767: Missing validation in DAST analyzer affecting all versions from 1
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-09
Published