Lucene search

K
nvd[email protected]NVD:CVE-2023-2825
HistoryMay 26, 2023 - 9:15 p.m.

CVE-2023-2825

2023-05-2621:15:16
CWE-22
web.nvd.nist.gov
2
cve-2023-2825
gitlab
path traversal
unauthenticated user
arbitrary files
server vulnerability
public project

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

9.3 High

AI Score

Confidence

High

0.159 Low

EPSS

Percentile

96.0%

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

Affected configurations

NVD
Node
gitlabgitlabMatch16.0.0community
OR
gitlabgitlabMatch16.0.0enterprise

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

9.3 High

AI Score

Confidence

High

0.159 Low

EPSS

Percentile

96.0%