CVE-2024-0402: Arbitrary file write while creating workspace
An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.5.8, 16.6 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace. This is a critical severity issue (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, 9.9). It is now mitigated in the latest release and is assigned CVE-2024-0402.
Other sources
An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.
— NVD
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-0402?
CVE-2024-0402 is considered a critical vulnerability due to its ability to allow authenticated users to write files to arbitrary locations on the GitLab server.
How do I fix CVE-2024-0402?
To fix CVE-2024-0402, upgrade to GitLab versions 16.6.6, 16.7.4, or 16.8.1 or later.
Who is affected by CVE-2024-0402?
CVE-2024-0402 affects all versions of GitLab CE/EE from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1.
What type of access is required to exploit CVE-2024-0402?
Exploitation of CVE-2024-0402 requires authenticated user access to the GitLab server.
What are the potential risks of CVE-2024-0402?
The potential risks of CVE-2024-0402 include unauthorized file creation and modification on the GitLab server, which could lead to data breaches or service disruption.