Описание
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page.
Ссылки
- Vendor Advisory
- ExploitVendor Advisory
- Permissions Required
- Vendor Advisory
- ExploitVendor Advisory
- Permissions Required
Уязвимые конфигурации
Конфигурация 1Версия от 2.0.0 (включая) до 3.0.55 (исключая)
cpe:2.3:a:gitlab:dynamic_application_security_testing_analyzer:*:*:*:*:*:*:*:*
EPSS
Процентиль: 27%
0.00098
Низкий
5 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-863
CWE-863
Связанные уязвимости
CVSS3: 6.5
github
почти 3 года назад
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page.
EPSS
Процентиль: 27%
0.00098
Низкий
5 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-863
CWE-863