First published: Tue Jan 18 2022(Updated: )
An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gitlab Gitlab | >=14.5<=14.5.3 | |
Gitlab Gitlab | >=14.5<=14.5.3 | |
Gitlab Gitlab | >=14.6<=14.6.2 | |
Gitlab Gitlab | >=14.6<=14.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.