Arbitrary File Write Vulnerability Affects GitLab Servers

CVE-2024-0402
9.9CRITICAL

Key Information

Vendor
Gitlab
Status
Gitlab
Vendor
CVE Published:
26 January 2024

Badges

😄 Trended👾 Exploit Exists📰 News Worthy

Summary

A critical vulnerability, CVE-2024-0402, has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. This vulnerability allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace. Although it has not been exploited in the wild, there is a potential for it to be exploited to deliver malware. GitLab has released patches for this vulnerability in versions 16.5.8, 16.6.6, 16.7.4, and 16.8.1. Additionally, the company has fixed four medium severity security holes in these releases. It is recommended that users update their installations immediately to mitigate the risk of exploitation and protect sensitive data.

Affected Version(s)

GitLab < 16.5.8

GitLab < 16.6.6

GitLab < 16.7.4

News Articles

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit exists.

  • Vulnerability started trending.

  • First article discovered by Penetration Testing

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database7 News Article(s)

Credit

This vulnerability has been discovered internally by GitLab team member [joernchen](https://gitlab.com/joernchen)
.