← Back to CVE List
Vulnerability Intelligence Report

CVE-2023-2825

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

Nuclei Template
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:5.8
EPSS Probability:71.64%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-22 ↗CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Affected Products & Versions

Vendor Product Affected Versions
GitLab GitLab 16.0.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Nuclei Template
SCANNER AVAILABLE
EPSS Score
71.641%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitLab Inc. · Vendor · USA
Reserved2023-05-20T00:00:00
Published2023-05-26T00:00:00
Last Updated2025-01-15T15:45:18

LINK COPIED TO CLIPBOARD