CRITICAL
CVE-2024-0402
CVSS
9.9
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.
Summary dbcve.org
A path traversal vulnerability in GitLab CE/EE allows authenticated users to write files to arbitrary locations on the server during workspace creation. This file write capability combined with the ability to write to any path makes remote code execution straightforward.
Mitigation
Upgrade GitLab to version 16.6.6, 16.7.4, 16.8.1 or later. If immediate patching is not possible, restrict or disable workspace creation features for untrusted users.
Weakness (CWE)
CWE-22
Path Traversal
EPSS Score
3.78%
Probability of exploitation in next 30 days
89.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.