An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.
Metrics
Affected Vendors & Products
References
History
Thu, 29 Aug 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
MITRE
Status: PUBLISHED
Assigner: GitLab
Published: 2024-01-26T01:02:39.052Z
Updated: 2024-08-29T15:04:54.380Z
Reserved: 2024-01-10T16:30:43.698Z
Link: CVE-2024-0402
Vulnrichment
No data.
NVD
Status : Modified
Published: 2024-01-26T01:15:08.920
Modified: 2024-11-21T08:46:30.360
Link: CVE-2024-0402
Redhat
No data.