HomePentest-Tools.com Logo

GitLab 16.0.0 - Path Traversal CVE-2023-2825

Severity
CVSSv3 Score
7.5
Vulnerability description

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups\n

Risk description

The risk exists that a remote unauthenticated attacker could exploit this vulnerability to read sensitive information from arbitrary files located on the file system of the server.

Recommendation

Upgrade GitLab to a version that is not affected by the path traversal vulnerability (CVE-2023-2825).

Codename
Not available
Detectable with
Network Scanner
Scan engine
Nuclei
Exploitable with Sniper
No
CVE Published
May 26, 2023
Detection added at
Software Type
Not available
Vendor
Not available
Product
Not available