CVE-2023-5117
CVSS 3.1 Score 3.7 of 10 (low)
Details
Published Dec 25, 2024
CWE ID 213
Summary
CVE-2023-5117 is a vulnerability affecting GitLab CE/EE versions prior to 17.6.0. This issue permits unauthenticated access to files uploaded as comments on confidential issues and epics of public projects, making them visible to anyone with the direct link to the file URL. Users were reportedly unaware of this vulnerability, potentially leading to sensitive data exposure. This security flaw could be exploited by attackers to gain unauthorized access to confidential information, emphasizing the importance of timely software updates.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GitLab
Affected Vendors
- GitLab Inc.