First published: Wed Feb 01 2023(Updated: )
A sensitive information leak issue has been discovered in all versions of DAST API scanner from 1.6.50 prior to 2.0.102, exposing the Authorization header in the vulnerability report
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab DAST API Scanner | >=1.6.50<2.0.102 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4206 is a sensitive information leak issue in all versions of DAST API scanner from 1.6.50 prior to 2.0.102.
The severity of CVE-2022-4206 is medium with a CVSS score of 6.5.
CVE-2022-4206 exposes the Authorization header in the vulnerability report of GitLab DAST API scanner.
To fix CVE-2022-4206, update GitLab DAST API scanner to version 2.0.102 or above.
You can find more information about CVE-2022-4206 at the following references: [link to CVE-2022-4206.json](https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4206.json) and [link to GitLab issue #383083](https://gitlab.com/gitlab-org/gitlab/-/issues/383083).