CVE-2026-85706: GitLab Community Edition and Enterprise Edition
GitLab Community Edition และ Enterprise Edition มีเส้นผ่านศูนย์กลางความเสียหายที่ช่วยให้ผู้ใช้ที่ไม่ได้รับการรับรองสามารถอ่านไฟล์ทางทวารหนั กเนื่องจากการปิดผนึกเส้นผ่านศูนย์กลางที่ไม่ถูกต้องและข้อบกพร่องในการบังคับใช้การรับรองใน API ของจัดเก็บข้อมูล
CISA (English)
GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.
- ผู้ผลิต
- GitLab
- ผลิตภัณฑ์
- Community Edition and Enterprise Edition
- ช่องโหว่
- GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- วันที่เพิ่ม
- 11 ก.ย. 2026
- กำหนดของ CISA (หน่วยงานรัฐบาลกลางสหรัฐฯ)
- 14 ก.ย. 2026
- การใช้ในการโจมตีด้วยแรนซัมแวร์
- ไม่ทราบ
- จุดอ่อน (CWE)
- CWE-35
แหล่งอ้างอิง
เว็บไซต์นี้สรุปแคตตาล็อกของ CISA เพื่อเป็นข้อมูลเท่านั้น ไม่ใช่คำแนะนำด้านความปลอดภัย โปรดปฏิบัติตามคำแนะนำของผู้ผลิตและประกาศอย่างเป็นทางการ
อัปเดตล่าสุด: · เวอร์ชันแคตตาล็อก 2026.10.02