| Severity | 
						
							
						 | 
					
					
						| Remote | 
						
							
						 | 
					
					
						| Type | 
						
							
								
									| - | 
									Unknown | 
								 
								
									| + | 
									Arbitrary filesystem access | 
								 
							 
						 | 
					
					
						| Description | 
						
							
								
									| + | 
									An issue has been discovered in GitLab CE/EE affecting all versions starting with 13.7.9. A specially crafted Wiki page allowed attackers to read arbitrary files on the server. The issue is fixed in GitLab versions 13.10.1, 13.9.5 and 13.8.7. | 
								 
							 
						 | 
					
					
						| References | 
						
							
								
									| + | 
									https://about.gitlab.com/releases/2021/03/31/security-release-gitlab-13-10-1-released/#kroki-arbitrary-file-readwrite | 
								 
								
									| + | 
									https://gitlab.com/gitlab-org/gitlab/-/issues/320919 | 
								 
								
									| + | 
									https://hackerone.com/reports/1098793 | 
								 
							 
						 | 
					
					
						| Notes | 
						
							
						 |