VendorsGitLabdynamic_application_security_testing_analyzerall versions
Vulnerabilities

GitLab Dynamic Application Security Testing (DAST) Analyzer

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2022-3767
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
Published 2023-03-09 · Modified
7.7EPSS 0.008
CVE-2022-4315
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page.
Published 2023-03-08 · Modified
6.5EPSS 0.008
CVE-2022-4317
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request headers in redirects.
Published 2023-03-09 · Modified
6.1EPSS 0.005
CVE-2023-0326
An issue has been discovered in GitLab DAST API scanner affecting all versions starting from 1.6.50 before 2.11.0, where Authorization headers was leaked in vulnerability report evidence.
Published 2023-03-27 · Modified
5.0EPSS 0.008