Path traversal in GitLab Enterprise Edition and Gitlab Community Edition - #VU54622
Published: July 8, 2021
Vulnerability identifier: #VU54622
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to read arbitrary files on the system.
The vulnerability exists due to input validation error within the design feature. A remote user can use a specially crafted design to ready contents of arbitrary files on the system.
Affected software
GitLab Enterprise Edition
Gitlab Community Edition
Gitlab Community Edition
Remediation
Install update from vendor's website.
GitLab Enterprise Edition - addressed in versions 13.11.7, 13.12.8, 14.0.4
Gitlab Community Edition - addressed in versions 13.11.7, 13.12.8, 14.0.4
Gitlab Community Edition - addressed in versions 13.11.7, 13.12.8, 14.0.4