According to the National Vulnerability Database, GitLab Community Edition and Enterprise Edition contain a path traversal vulnerability. The vulnerability allows an unauthenticated user to read arbitrary files. The cause is improper path confinement and missing authentication enforcement in the repository commits API.