CVE-2022-4206

MEDIUM

Gitlab Dast API Scanner < 2.0.102 - Information Disclosure

Title source: rule

Description

A sensitive information leak issue has been discovered in all versions of DAST API scanner from 1.6.50 prior to 2.0.102, exposing the Authorization header in the vulnerability report

Scores

CVSS v3 5.0
EPSS 0.0015
EPSS Percentile 36.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Classification

CWE
CWE-200
Status published

Affected Products (1)

gitlab/dast_api_scanner < 2.0.102

Timeline

Published Feb 01, 2023
Tracked Since Feb 18, 2026