CyberHighConfirmedDeveloping
7.5
GitLab critical unauthenticated file-read flaw under active internet-wide probing
CyberScoop·about 16 hours ago
GitLab disclosed CVE-2023-2825, a maximum-severity path traversal vulnerability, and urged users to patch immediately. The flaw could allow unauthorized file access or code execution, posing a significant supply-chain risk given GitLab's widespread use in software development. Exploitation details are not yet public, but the urgency suggests active or imminent threat.
Entities