CVE-2026-85706: GitLab Community Edition and Enterprise Edition
GitLab Community Edition 및 Enterprise Edition에는 불확실한 사용자를 읽을 수있는 경로 트레이널 취약점이 포함되어 있습니다. 부적절한 경로 confinement 및 repository에서 인증 된 강제로 인해 임의 파일을 읽을 수 있습니다. API.
CISA (English)
GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.
- 공급업체
- GitLab
- 제품
- Community Edition and Enterprise Edition
- 취약점
- GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- 추가일
- 2026. 9. 11.
- CISA 조치 기한(미국 연방기관)
- 2026. 9. 14.
- 랜섬웨어 공격 악용
- 알 수 없음
- 약점(CWE)
- CWE-35
참고 자료
이 사이트는 정보 제공 목적으로 CISA 카탈로그를 요약한 것이며 보안 조언이 아닙니다. 공급업체 안내와 공식 권고를 따르세요.
최종 업데이트: · 카탈로그 버전 2026.10.02