Arbitrary File Write Vulnerability in GitLab CE/EE

Arbitrary File Write Vulnerability in GitLab CE/EE

CVE-2024-0402 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

Learn more about our Cis Benchmark Audit For Google Workspace.