CVE-2022-4206: Infoleak
A sensitive information leak issue has been discovered in all versions of DAST API scanner from 1.6.50 prior to 2.0.102, exposing the Authorization header in the vulnerability report
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4206?
CVE-2022-4206 is a sensitive information leak issue in all versions of DAST API scanner from 1.6.50 prior to 2.0.102.
What is the severity of CVE-2022-4206?
The severity of CVE-2022-4206 is medium with a CVSS score of 6.5.
How does CVE-2022-4206 affect GitLab DAST API scanner?
CVE-2022-4206 exposes the Authorization header in the vulnerability report of GitLab DAST API scanner.
How can I fix CVE-2022-4206?
To fix CVE-2022-4206, update GitLab DAST API scanner to version 2.0.102 or above.
Where can I find more information about CVE-2022-4206?
You can find more information about CVE-2022-4206 at the following references: [link to CVE-2022-4206.json](https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4206.json) and [link to GitLab issue #383083](https://gitlab.com/gitlab-org/gitlab/-/issues/383083).