Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-2825
HistoryMay 26, 2023 - 9:15 p.m.

Path traversal

2023-05-2621:15:00
PRIOn knowledge base
www.prio-n.com
5
gitlab
ce
ee
version 16.0.0
path traversal
vulnerability
unauthenticated user
arbitrary files
public project
nested groups
nvd

7.2 High

AI Score

Confidence

High

0.159 Low

EPSS

Percentile

96.0%

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

CPENameOperatorVersion
gitlabeq16.0.0
gitlabeq16.0.0

7.2 High

AI Score

Confidence

High

0.159 Low

EPSS

Percentile

96.0%