CVE-2022-3767: Input Validation
Published Mar 9, 2023
·Updated
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
Affected Software
1 affected component
GitLab Dynamic Application Security Testing Analyzer>=1.11.0<3.0.32
Remediation
Patch Available
Event History
Mar 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-3767?
CVE-2022-3767 is a vulnerability that affects the Gitlab Dynamic Application Security Testing Analyzer.
2
How does CVE-2022-3767 impact Gitlab?
CVE-2022-3767 allows custom request headers to be sent with every request, regardless of the host, in versions 1.11.0 to 3.0.32 of Gitlab Dynamic Application Security Testing Analyzer.
3
What is the severity of CVE-2022-3767?
CVE-2022-3767 has a severity rating of high (6.5).
4
Which versions of Gitlab are affected by CVE-2022-3767?
Versions 1.11.0 to 3.0.32 of Gitlab Dynamic Application Security Testing Analyzer are affected by CVE-2022-3767.
5
How can I fix CVE-2022-3767?
To fix CVE-2022-3767, update Gitlab Dynamic Application Security Testing Analyzer to a version newer than 3.0.32.