First published: Fri Jan 26 2024(Updated: )
An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=16.0.0<16.5.8 | |
GitLab | >=16.0.0<16.5.8 | |
GitLab | >=16.6.0<16.6.6 | |
GitLab | >=16.6.0<16.6.6 | |
GitLab | >=16.7.0<16.7.4 | |
GitLab | >=16.7.0<16.7.4 | |
GitLab | =16.8.0 | |
GitLab | =16.8.0 |
Upgrade to versions 16.8.1, 16.7.4, 16.6.6, 16.5.8 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0402 is considered a critical vulnerability due to its ability to allow authenticated users to write files to arbitrary locations on the GitLab server.
To fix CVE-2024-0402, upgrade to GitLab versions 16.6.6, 16.7.4, or 16.8.1 or later.
CVE-2024-0402 affects all versions of GitLab CE/EE from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1.
Exploitation of CVE-2024-0402 requires authenticated user access to the GitLab server.
The potential risks of CVE-2024-0402 include unauthorized file creation and modification on the GitLab server, which could lead to data breaches or service disruption.