QID 378519
Date Published: 2023-05-25
QID 378519: GitLab Path Traversal Vulnerability (CVE-2023-2825)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
Affected Versions:
GitLab version: 16.0.0
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.
Solution
The vendor has released a patch for this vulnerability. For more information, please visit GitLab advisory
Vendor References
CVEs related to QID 378519
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Advisory |
|