Vulnerability record · CVE-2023-34598 · published 29 June 2023
CVE-2023-34598: Gibbon local file inclusion via path traversal
Gibbonedu · Gibbon
Gibbon v25.0.0 is vulnerable to local file inclusion, allowing files within the installation folder to be read into the server's response. The flaw is a path traversal issue (CWE-22) and is rated critical by NVD. It matters because exposed configuration or credential files can hand an attacker the keys to the application and its data.
Description
Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation folder in the server's response.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and a public exploit plus high EPSS make this an urgent fix despite the absence of KEV listing.
What it is
Gibbon v25.0.0 is vulnerable to local file inclusion, allowing files within the installation folder to be read into the server's response. The flaw is a path traversal issue (CWE-22) and is rated critical by NVD. It matters because exposed configuration or credential files can hand an attacker the keys to the application and its data.
Impact
An attacker can read files present in the Gibbon installation folder, which may include configuration and credential material. That access can enable further compromise of the application and its underlying data.
Attack surface
The CVSS vector is network-reachable with no privileges and no user interaction required (AV:N/AC:L/PR:N/UI:N). The description does not name the specific endpoint or parameter, so the exact request path is not documented in this record.
Exploitation
A public exploit reference exists on GitHub, and EPSS is high at roughly 0.47 (98.8th percentile), indicating elevated likelihood of exploitation. The CVE is not listed in CISA KEV, so confirmed in-the-wild use is not established by this record.
What to do
- Upgrade Gibbon to a version later than v25.0.0 that fixes the path traversal; verify the fixed release with the vendor before deploying.
- If immediate upgrade is not possible, restrict network access to the Gibbon instance to trusted users and networks.
- Harden the web server to block traversal sequences in request paths and deny access to sensitive files in the installation folder.
- Run Gibbon with least privilege and move configuration or credential files outside the web-accessible installation directory where feasible.
- Monitor vendor advisories for a confirmed patched version, since this record does not specify one.
Detection
- Search web server and application logs for request paths containing traversal sequences such as ../ or encoded variants targeting Gibbon endpoints.
- Alert on responses returning file contents from the installation directory, especially configuration or credential files.
- Baseline normal Gibbon request patterns and flag anomalous file-inclusion style requests from single sources.
- Review outbound or follow-on activity from the Gibbon host for signs of credential use after suspected file reads.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/maddsec/CVE-2023-34598 | ExploitThird Party Advisory |
| https://github.com/maddsec/CVE-2023-34598 | ExploitThird Party Advisory |
Track CVE-2023-34598 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-34598), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.