CVE-2023-2825
EUVD-2023-3427626.05.2023, 21:15
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gitlab | gitlab | 16.0.0 |
| gitlab | gitlab | 16.0.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
References