References https://nvd.nist.gov/vuln/detail/CVE-2023-2825 https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2825.json https://about.gitlab.com/releases/2023/05/23/critical-security-release-gitlab-16-0-1-released/ https://github.com/Occamsec/CVE-2023-2825 https://labs.watchtowr.com/gitlab-arbitrary-file-read-gitlab-cve-2023-2825-analysis/ https://www.h3c.com/cn/d_202309/1928970_30003_0.htm https://www.secrss.com/articles/54947 https://avd.aliyun.com/detail?id=AVD-2023-2825 https://www.venustech.com.cn/new_type/aqtg/20230524/25650.html https://www.cnvd.org.cn/flaw/show/CNVD-2023-61357 https://blogs.juniper.net/en-us/threat-research/cve-2023-2825-gitlab-arbitrary-path-traversal-vulnerability https://www.sentinelone.com/blog/gitlab-cve-2023-2825/ https://www.tenable.com/plugins/nessus/176251
Related VulnerabilitiesPoCCVE-2026-85706: GitLab CE/EE <=19.1.7/19.2.5/19.3.1 - Arbitrary File ReadGitLab CE/EE /api/graphql 未授权访问漏洞(CVE-2026-19478)PoCCVE-2026-19478: GitLab CE/EE - GraphQL @gl_introduced Arbitrary Method InvocationPoCCVE-2021-22175: GitLab CI Lint API - Server-Side Request ForgeryGitLab GitLab CE/EE 权限管理不当漏洞GitLab CE/EE GraphQL 身份验证缺陷漏洞GitLab CE/EE 资源分配控制不当漏洞 可导致拒绝服务gitlab-api-user-enum: GitLab - User Information Disclosure Via Open APIPoCCVE-2024-45409: GitLab - SAML Authentication BypassPoCCVE-2025-25291: GitLab - SAML Authentication BypassPoCCVE-2019-6793: GitLab Enterprise Edition - Server-Side Request ForgeryPoCCVE-2020-2096: Jenkins Gitlab Hook <=1.4.2 - Cross-Site ScriptingPoCCVE-2020-26413: Gitlab CE/EE 13.4 - 13.6.2 - Information Disclosure