Vulnerability record · CVE-2023-2825 · published 26 May 2023
CVE-2023-2825: GitLab CE/EE path traversal allows unauthenticated arbitrary file read
Gitlab · Gitlab
GitLab CE/EE version 16.0.0 contains a path traversal flaw (CWE-22) that lets an unauthenticated attacker read arbitrary files on the server. It is exploitable only when an attachment exists in a public project nested within at least five groups, which narrows the affected population but leaves exposed instances fully readable. The CVSS 3.1 base score is 7.5 (HIGH) with confidentiality impact only.
Description
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable arbitrary file read with a 7.5 CVSS score and very high EPSS, though exploitation requires a specific public-project nesting precondition.
What it is
GitLab CE/EE version 16.0.0 contains a path traversal flaw (CWE-22) that lets an unauthenticated attacker read arbitrary files on the server. It is exploitable only when an attachment exists in a public project nested within at least five groups, which narrows the affected population but leaves exposed instances fully readable. The CVSS 3.1 base score is 7.5 (HIGH) with confidentiality impact only.
Impact
An attacker gains read access to arbitrary files on the GitLab server, which can expose repository data, configuration and secrets stored on the host. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network with no authentication and no user interaction (AV:N/AC:L/PR:N/UI:N). The precondition is a public project nested within at least five groups that contains an attachment.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.716 probability (99.4th percentile), indicating strong likelihood of attempted exploitation. Reference tags are advisory and HackerOne report links only, with no public exploit tag supplied.
What to do
- Upgrade GitLab CE/EE from 16.0.0 to a fixed release as the primary action.
- If immediate upgrade is not possible, restrict or remove public projects nested five or more groups deep and audit attachments in those projects.
- Reduce nesting depth of public projects and review group visibility settings to eliminate the required precondition.
- Monitor GitLab advisories and the vendor CVE record for the fixed version and backport guidance.
- Treat any host running 16.0.0 as potentially compromised and review file access logs.
Detection
- Search GitLab access logs for requests to attachment endpoints containing traversal sequences such as ../ or encoded variants.
- Alert on unauthenticated requests to project attachment paths that return 200 with unexpected content types or sizes.
- Inventory GitLab instances and flag any running version 16.0.0.
- Correlate outbound or file-read anomalies on GitLab hosts with attachment endpoint access from unauthenticated sessions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2825.json | Third Party Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/412371 | Broken Link |
| https://hackerone.com/reports/1994725 | Permissions RequiredThird Party Advisory |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2825.json | Third Party Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/412371 | Broken Link |
| https://hackerone.com/reports/1994725 | Permissions RequiredThird Party Advisory |
Track CVE-2023-2825 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-2825), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.