Site icon TheCyberThrone

GitLab fixes Critical Vulnerability -CVE-2024-0402

Advertisements

GitLab has addressed a critical severity vulnerability that could allow an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

The vulnerability tracked as CVE-2024-0402, with a CVSS score of 9.9 affects both GitLab Community Edition (CE) and Enterprise Edition (EE).

As per the advisory, an issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.5.8, 16.6 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

Advertisements

GitLab urged users to immediately upgrade all GitLab installations to the latest versions (16.5.8, or 16.6.6, 16.7.4, or 16.8.1) to fix CVE-2024-0402.

GitLab also fixed several security flaws in this update:

Exit mobile version