CVE-2023-3385
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
6.5
MEDIUM
CVSS 3.1
EPSS 0.10%
Description
An issue has been discovered in GitLab affecting all versions starting from 8.10 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Under specific circumstances, a user importing a project 'from export' could access and read unrelated files via uploading a specially crafted file. This was due to a bug in `tar`, fixed in [`tar-1.35`](https://lists.gnu.org/archive/html/info-gnu/2023-07/msg00005.html).
How to fix CVE-2023-3385
To remediate CVE-2023-3385, upgrade the affected package to a fixed version below.
- —upgrade to 16.0.8 or later
Is CVE-2023-3385 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 8.10.0, < 16.0.8, >= 16.1.0, < 16.1.3, >= 16.2.0, < 16.2.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |