
Exploit script for CVE-2023-2825, an unauthenticated directory traversal vulnerability in GitLab 16.0.0 allowing arbitrary file read on servers with public nested group projects.
(Unauthenticated) Directory traversal leads to file read.
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.
Unauthenticated if there already is a repo with nested groups, otherwise a account with permission to create groups is needed.