HIGH

CVE-2023-2825

Gitlab GitLab 2023-05-26 CVSS v3.1
CVSS
7.5

Description

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

Summary dbcve.org

A path traversal vulnerability in GitLab CE/EE version 16.0.0 allows unauthenticated attackers to read arbitrary files on the server. The attack requires a public project nested within at least five groups that contains an attachment, which can then be accessed via path traversal to traverse outside the intended directory.

Mitigation

Upgrade GitLab from version 16.0.0 to a patched version (16.0.1 or later). If immediate upgrade is not feasible, restrict public project creation and monitor for unauthorized file access attempts.

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

71.64%
Probability of exploitation in next 30 days
99.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE