CVE-2023-0326: Medium severity gitlab dynamic application security testing analyzer vulnerability
An issue has been discovered in GitLab DAST API scanner affecting all versions starting from 1.6.50 before 2.11.0, where Authorization headers was leaked in vulnerability report evidence.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-0326.
What is the severity rating of CVE-2023-0326?
CVE-2023-0326 has a severity rating of 4.3 (medium).
Which versions of GitLab DAST API scanner are affected?
All versions starting from 1.6.50 before 2.11.0 of GitLab DAST API scanner are affected.
What is the impact of this vulnerability?
This vulnerability allows leaked Authorization headers in the vulnerability report evidence.
Is there any additional information available?
Yes, you can find additional information and references at the following links: [CVE-2023-0326 JSON](https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0326.json), [GitLab Issue #388132](https://gitlab.com/gitlab-org/gitlab/-/issues/388132), [HackerOne Report #1826896](https://hackerone.com/reports/1826896).