CVE-2022-4317

CWE-601Open Redirect4 documents4 sources
Severity
6.1MEDIUM
EPSS
0.3%
top 45.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 9

Description

An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request headers in redirects.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:NExploitability: 3.1 | Impact: 1.4

Affected Packages2 packages

CVEListV5gitlab/dast>=1.47, <3.0.51

🔴Vulnerability Details

2
GHSA
GHSA-4mvf-qm8g-c6mp: An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 12023-03-09
CVEList
CVE-2022-4317: An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 12023-03-09

📋Vendor Advisories

1
GitLab
CVE-2022-4317: An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request headers in re2023-03-09
CVE-2022-4317 (MEDIUM CVSS 6.1) | An issue has been discovered in Git | cvebase.io