Описание
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| esm-apps/xenial | ignored | not maintainable |
| esm-infra/focal | DNE | |
| focal | DNE | |
| jammy | DNE | |
| kinetic | DNE | |
| trusty | ignored | end of standard support |
| upstream | needs-triage | |
| xenial | ignored | end of standard support |
Показывать по
10
Ссылки на источники
7.7 High
CVSS3
Связанные уязвимости
CVSS3: 7.7
nvd
почти 3 года назад
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
CVSS3: 7.7
debian
почти 3 года назад
Missing validation in DAST analyzer affecting all versions from 1.11.0 ...
CVSS3: 6.5
github
почти 3 года назад
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
7.7 High
CVSS3