CRITICAL

CVE-2024-0402

Gitlab GitLab 2024-01-26 CVSS v3.1
CVSS
9.9

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

Summary dbcve.org

A path traversal vulnerability in GitLab CE/EE allows authenticated users to write files to arbitrary locations on the server during workspace creation. This file write capability combined with the ability to write to any path makes remote code execution straightforward.

Mitigation

Upgrade GitLab to version 16.6.6, 16.7.4, 16.8.1 or later. If immediate patching is not possible, restrict or disable workspace creation features for untrusted users.

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

3.78%
Probability of exploitation in next 30 days
89.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE