CVE-2023-5117: Exposure of Sensitive Information Due to Incompatible Policies in GitLab
An issue was discovered in GitLab CE/EE affecting all versions before 17.6.0 in which users were unaware that files uploaded to comments on confidential issues and epics of public projects could be accessed without authentication via a direct link to the uploaded file URL.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5117?
CVE-2023-5117 is considered a high severity vulnerability due to the potential exposure of confidential information.
How do I fix CVE-2023-5117?
To fix CVE-2023-5117, upgrade GitLab CE/EE to version 17.6.0 or later.
Who is affected by CVE-2023-5117?
CVE-2023-5117 affects all versions of GitLab CE/EE prior to 17.6.0.
What are the risks associated with CVE-2023-5117?
The main risk associated with CVE-2023-5117 is unauthorized access to confidential files uploaded in comments on public project issues.
What should users do if they cannot upgrade GitLab due to CVE-2023-5117?
If upgrade is not possible, users should consider restricting access to public project issues or securely managing file uploads.