Описание
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7.9 before 13.8.7, all versions starting from 13.9 before 13.9.5, and all versions starting from 13.10 before 13.10.1. A specially crafted Wiki page allowed attackers to read arbitrary files on the server.
Ссылки
- Vendor Advisory
- ExploitIssue TrackingPatchVendor Advisory
- ExploitIssue TrackingThird Party Advisory
- Vendor Advisory
- ExploitIssue TrackingPatchVendor Advisory
- ExploitIssue TrackingThird Party Advisory
Уязвимые конфигурации
Одно из
EPSS
7.5 High
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7.9 before 13.8.7, all versions starting from 13.9 before 13.9.5, and all versions starting from 13.10 before 13.10.1. A specially crafted Wiki page allowed attackers to read arbitrary files on the server.
An issue has been discovered in GitLab CE/EE affecting all versions st ...
An issue has been discovered in GitLab CE/EE affecting all versions starting with 13.7.9. A specially crafted Wiki page allowed attackers to read arbitrary files on the server.
EPSS
7.5 High
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2