Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/377473 | issue tracking patch vendor advisory exploit |
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3767.json | vendor advisory |