CVE-2023-2825
26.05.2023, 21:15
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 16.0.0 |
gitlab | gitlab | 16.0.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References