An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwrite certain specific paths on the server. Affected versions are: >8.14, <13.3.9,>13.4, <13.4.5,>13.5, <13.5.2.
Publication date: Thu, 19 Nov 2020 06:15:00 +0000