CVE-2024-2434: Path Traversal leads to DoS and Restricted File Read
Published Apr 24, 2024
·Updated
An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.
Affected Software
7 affected componentsFixes available
GitLab GitLab>=16.9.0<16.9.6
GitLab GitLab>=16.9.0<16.9.6
GitLab GitLab>=16.10.0<16.10.4
GitLab GitLab>=16.10.0<16.10.4
GitLab GitLab=16.11.0
GitLab GitLab=16.11.0
GitLab GitLab>=16.9<16.9.6, >=16.10<16.10.4, >=16.11<16.11.1
16.9.616.10.416.11.1
Remediation
Information
Upgrade to versions 16.9.6, 16.10.4, 16.11.1 or above.
Event History
Apr 25, 2024
CVE Published
via MITRE·11:02 AM
Data Sourced
via MITRE·11:02 AM
RemedyDescriptionSeverityWeakness
Apr 22, 2026
Data Sourced
via GitLab·08:52 AM
DescriptionSeverityAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2024-2434?
CVE-2024-2434 has a medium severity rating due to its potential to cause denial of service and restricted file read.
2
How do I fix CVE-2024-2434?
To fix CVE-2024-2434, upgrade GitLab to version 16.9.6 or later, 16.10.4 or later, or 16.11.1 or later.
3
Which GitLab versions are affected by CVE-2024-2434?
CVE-2024-2434 affects GitLab CE/EE versions prior to 16.9.6, 16.10.4, and 16.11.1.
4
What type of vulnerability is CVE-2024-2434?
CVE-2024-2434 is a path traversal vulnerability that can lead to denial of service.
5
Can CVE-2024-2434 lead to unauthorized access?
CVE-2024-2434 does not directly allow unauthorized access, but it can lead to restricted file reads.