CVE-2023-2825
Description
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.
Summary dbcve.org
A path traversal vulnerability in GitLab CE/EE version 16.0.0 allows unauthenticated attackers to read arbitrary files on the server. The attack requires a public project nested within at least five groups that contains an attachment, which can then be accessed via path traversal to traverse outside the intended directory.
Mitigation
Upgrade GitLab from version 16.0.0 to a patched version (16.0.1 or later). If immediate upgrade is not feasible, restrict public project creation and monitor for unauthorized file access attempts.