GitLab DAST Analyzer Vulnerability: Unauthorized Custom Request Headers on Authentication Page

GitLab DAST Analyzer Vulnerability: Unauthorized Custom Request Headers on Authentication Page

CVE-2022-4315 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page.

Learn more about our Web Application Penetration Testing UK.