Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwrite certain specific paths on the server. Affected versions are: >=8.14, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- gitlab / GitLab CE/EE>=8.14 – >=8.14
- gitlab / GitLab CE/EE<13.3.9 – <13.3.9
- gitlab / GitLab CE/EE>=13.4 – >=13.4
- gitlab / GitLab CE/EE<13.4.5 – <13.4.5
- gitlab / GitLab CE/EE>=13.5 – >=13.5
- gitlab / GitLab CE/EE<13.5.2 – <13.5.2