/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2023-5117

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-5117

CGA ID

CGA-8f7x-4c8w-gw82

Description

An issue was discovered in GitLab CE/EE affecting all versions before 17.6.0 in which users were unaware that files uploaded to comments on confidential issues and epics of public projects could be accessed without authentication via a direct link to the uploaded file URL.

References

  • https://images.chainguard.dev/security/CGA-8f7x-4c8w-gw82

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs