Related Vulnerabilities: CVE-2021-22203  

An issue has been discovered in GitLab CE/EE affecting all versions starting with 13.7.9. A specially crafted Wiki page allowed attackers to read arbitrary files on the server. The issue is fixed in GitLab versions 13.10.1, 13.9.5 and 13.8.7.

Severity High

Remote Yes

Type Arbitrary filesystem access

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting with 13.7.9. A specially crafted Wiki page allowed attackers to read arbitrary files on the server. The issue is fixed in GitLab versions 13.10.1, 13.9.5 and 13.8.7.

AVG-1770 gitlab 13.9.4-1 13.10.1-1 Critical Testing

https://about.gitlab.com/releases/2021/03/31/security-release-gitlab-13-10-1-released/#kroki-arbitrary-file-readwrite
https://gitlab.com/gitlab-org/gitlab/-/issues/320919
https://hackerone.com/reports/1098793