Critical severity10.0NVD Advisory· Published May 26, 2023· Updated Jun 17, 2026
CVE-2023-2825
CVE-2023-2825
Description
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: =16.0.0
=16.0.0+ 1 more
- (no CPE)range: =16.0.0
- (no CPE)range: 16.0.0
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2825.jsonnvdThird Party Advisory
- hackerone.com/reports/1994725nvdPermissions RequiredThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/412371nvdBroken Link
News mentions
1- GitLab Critical Security Release: 16.0.1GitLab Security Releases · May 23, 2023