A sensitive information leak issue has been discovered in all versions of DAST API scanner from 1.6.50 prior to 2.0.102, exposing the Authorization header in the vulnerability report
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/383083 | vendor advisory issue tracking exploit |
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4206.json | vendor advisory |