Back to the feed

~/article/gitlab-community-edition-and-enterprise-edition-path-traversal-vulnerabi-u9fgzw
criticalSource: CISA

GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.

Read at the source

Summary written for cymesh.dev. The full article lives at CISA.

Referenced CVEs

Topics

~/cymesh.net

This is what cymesh.net is for

Certificate and hostname problems are the ones you find out about from your users. cymesh.net finds them first.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/gitlab-community-edition-and-enterprise-edition-path-traversal-vulnerabi-u9fgzw