Critical severity10.0NVD Advisory· Published May 26, 2023· Updated Jun 17, 2026
CVE-2023-2825
CVE-2023-2825
Description
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:gitlab:gitlab:16.0.0:*:*:*:community:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:16.0.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:16.0.0:*:*:*:enterprise:*:*:*
- (no CPE)range: 16.0.0
- (no CPE)range: =16.0.0
- Range: =16.0.0
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2825.jsonnvdThird Party Advisory
- hackerone.com/reports/1994725nvdPermissions RequiredThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/412371nvdBroken Link
News mentions
1- GitLab Critical Security Release: 16.0.1GitLab Security Releases · May 23, 2023