CVE-2023-2825 : GITLAB COMMUNITY EDITION/ENTERPRISE EDITION 16.0.0 PUBLIC PROJECT PATH TRAVERSAL

Description

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

References

https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2825.json

https://gitlab.com/gitlab-org/gitlab/-/issues/412371

https://hackerone.com/reports/1994725

For More Information

MITRE

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2023-2825 : GITLAB COMMUNITY EDITION/ENTERPRISE EDITION 16.0.0 PUBLIC PROJECT PATH TRAVERSAL

CVE-2023-2825 : GITLAB COMMUNITY EDITION/ENTERPRISE EDITION 16.0.0 PUBLIC PROJECT PATH TRAVERSAL

Description An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a

CVE-2023-2851 : AGT TECH CEPPATRON SQL INJECTION

CVE-2023-2851 : AGT TECH CEPPATRON SQL INJECTION

Description Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in AGT Tech Ceppatron allows Command

CVE-2023-2868 : BARRACUDA EMAIL SECURITY GATEWAY UP TO 9.2.0.006 TAR FILE COMMAND INJECTION

CVE-2023-2868 : BARRACUDA EMAIL SECURITY GATEWAY UP TO 9.2.0.006 TAR FILE COMMAND INJECTION

Description A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions