S4E just found a medium-severity finding from directory listing detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2023-2825

7.5
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
gitlab
Updated Sep 22, 2026View on NVD →
S4E scanner

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →