9.9
CVSSv3

CVE-2024-0402

Published: 26/01/2024 Updated: 31/01/2024
CVSS v3 Base Score: 9.9 | Impact Score: 6 | Exploitability Score: 3.1
VMScore: 0

Vulnerability Summary

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 16.6.6, 16.7 before 16.7.4, and 16.8 before 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab 16.8.0

gitlab gitlab

Github Repositories

CVE-2024-0402 Gitlab arbitrary file write/RCE

CVE-2024-0402-RCE CVE-2024-0402 Gitlab arbitrary file write/RCE CVE-2024-0402 is an arbitary file write which affects Gitlab About: The advisory mentioned it as file write to arbitary locations not mentioning the RCE which you can achieve using this vulnerability which probably trying to bring the risk of mass exploitation to minimum possible level after digging and def'