Threat Advisory

GitLab Strongly Recommends Patching Max Severity Flaw

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

A new critical vulnerability, identified as CVE-2023-2825, has been discovered, featuring a path traversal flaw with a maximum severity rating of 10.0 on the CVSS v3.1 scale. The recently uncovered vulnerability, denoted as CVE-2023-2825, exclusively affects GitLab Community Edition (CE) and Enterprise Edition (EE) version 16.0.0, while earlier versions remain unaffected.[/subscribe_to_unlock_form]

Summary:

A new critical vulnerability, identified as CVE-2023-2825, has been discovered, featuring a path traversal flaw with a maximum severity rating of 10.0 on the CVSS v3.1 scale. The recently uncovered vulnerability, denoted as CVE-2023-2825, exclusively affects GitLab Community Edition (CE) and Enterprise Edition (EE) version 16.0.0, while earlier versions remain unaffected.[emaillocker id="1283"]

The vulnerability arises due to a path traversal issue, enabling an unauthenticated attacker to access arbitrary files on the server. This can occur when a public project contains an attachment and is nested within a minimum of five groups. Exploiting CVE-2023-2825 has the potential to expose a wide range of sensitive data, such as proprietary software code, user credentials, tokens, files, and various other confidential information. Given the requirement outlined, it appears that the problem lies in GitLab's handling or resolution of paths for attached files that are deeply nested within multiple levels of group hierarchy. However, due to the critical nature of this vulnerability and its recent discovery, the vendor has provided limited details at this time.

One mitigating factor is that the vulnerability can only be exploited in specific circumstances. For instance, it requires the presence of an attachment within a public project nested within a minimum of five groups. Not all GitHub projects follow this structure, reducing the overall risk.

Recommendations:

  • If you are using Gitlab version 16.0.0 then we strongly recommend you update to latest GitLab version 16.0.1

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/gitlab-strongly-recommends-patching-max-severity-flaw-asap/

[/emaillocker]
crossmenu