Description
An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.
Problem types
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
16.9 (semver) before 16.9.6
16.10 (semver) before 16.10.4
16.11 (semver) before 16.11.1
Credits
Thanks [pwnie](https://hackerone.com/pwnie) for reporting this vulnerability through our HackerOne bug bounty program
References
gitlab.com/gitlab-org/gitlab/-/issues/450303 (GitLab Issue #450303)
hackerone.com/reports/2401952 (HackerOne Bug Bounty Report #2401952)
gitlab.com/gitlab-org/gitlab/-/issues/450303 (GitLab Issue #450303)
hackerone.com/reports/2401952 (HackerOne Bug Bounty Report #2401952)