---
title: "CVE-2016-9086\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2016-9086?format=md
keywords: index, follow
---

# CVE-2016-9086

Publication date 3 November 2016

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**6.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2016-9086?format=md#impact-score)

Toggle side navigation

## Description

GitLab versions 8.9.x and above contain a critical security flaw in the
"import/export project" feature of GitLab. Added in GitLab 8.9, this
feature allows a user to export and then re-import their projects as tape
archive files (tar). All GitLab versions prior to 8.13.0 restricted this
feature to administrators only. Starting with version 8.13.0 this feature
was made available to all users. This feature did not properly check for
symbolic links in user-provided archives and therefore it was possible for
an authenticated user to retrieve the contents of any file accessible to
the GitLab service account. This included sensitive files such as those
that contain secret tokens used by the GitLab service to authenticate
users. GitLab CE and EE versions 8.13.0 through 8.13.2, 8.12.0 through
8.12.7, 8.11.0 through 8.11.10, 8.10.0 through 8.10.12, and 8.9.0 through
8.9.11 are affected.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| gitlab | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Ignored end of life |
| 17.04 zesty | Ignored end of life |
| 16.10 yakkety | Ignored end of life |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

6.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9086)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2016-9086)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2016-9086)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2016-9086)

### Other references

* <https://about.gitlab.com/2016/11/02/cve-2016-9086-patches/>
* <https://www.cve.org/CVERecord?id=CVE-2016-9086>
