Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
Published Aug 1, 2023
6.5
MEDIUMCVSS 3.1
EPSS 0.86%
Description
An issue has been discovered in GitLab affecting all versions starting from 8.10 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Under specific circumstances, a user importing a project 'from export' could access and read unrelated files via uploading a specially crafted file. This was due to a bug in `tar`, fixed in [`tar-1.35`](https://lists.gnu.org/archive/html/info-gnu/2023-07/msg00005.html).
Affected products
-
- Version 16.1.0StatusaffectedConstraints<16.1.3
- Version 16.2.0StatusaffectedConstraints<16.2.2
- Version 8.10StatusaffectedConstraints<16.0.8
- Version
-
- Version 16.1.0StatusaffectedConstraints<16.1.3
- Version 16.2.0StatusaffectedConstraints<16.2.2
- Version 8.10StatusaffectedConstraints<16.0.8
- Version
Red Hat OpenShift Container Platform 4
openshift4/ose-console
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 16.2.2, 16.1.3, 16.0.8 or above.
Red Hat statement
The GitLab package used in OpenShift is a GitLab API NodeJS library which is not affected by CVE-2023-3385.
References (7)
- https://access.redhat.com/security/cve/CVE-2023-3385 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2228523 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-44052 Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/416161 issue-trackingBroken Link
- https://hackerone.com/reports/2032730 technical-descriptionexploitpermissions-requiredPermissions Required
- https://nvd.nist.gov/vuln/detail/CVE-2023-3385
- https://www.cve.org/CVERecord?id=CVE-2023-3385
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-3385 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2228523 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-44052 | Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/416161 | issue-trackingBroken Link | |
| https://hackerone.com/reports/2032730 | technical-descriptionexploitpermissions-requiredPermissions Required | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-3385 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-3385 |
Change history (0)
No recorded changes yet.