Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.
{
"versions": [
{
"introduced": "12.8.0"
},
{
"fixed": "13.3.9"
},
{
"introduced": "12.8.0"
},
{
"fixed": "13.3.9"
},
{
"introduced": "13.5.0"
},
{
"fixed": "13.5.2"
},
{
"introduced": "13.5.0"
},
{
"fixed": "13.5.2"
}
]
}