CVE-2022-4315

MEDIUM

GitLab DAST Analyzer 2.0-3.0.54 - Incorrect Authorization via Custom Request Headers

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page.

Scores

CVSS v3 5.0
EPSS 0.0020
EPSS Percentile 42.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
gitlab/dynamic_application_security_testing_analyzer 2.0.0 - 3.0.55
Published Mar 08, 2023
Tracked Since Feb 18, 2026