CyberRota Analysis
AI-GeneratedGitLab versions prior to 19.1.8, 19.2.6, and 19.3.2 are vulnerable to a critical flaw that allows unauthenticated users to read arbitrary files from the server, stemming from improper path confinement and lack of authentication enforcement in the repository commits API. This vulnerability poses a significant risk to sensitive data exposure, making it imperative for all GitLab users, particularly those managing sensitive repositories, to prioritize immediate updates to the latest versions. Organizations relying on GitLab for version control should act swiftly to mitigate potential data breaches.
Original NVD Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.