CVE-2024-0402
Published Jan 26, 2024
Last updated 9 months ago
Overview
- Description
- An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.
- Source
- cve@gitlab.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.9
- Impact score
- 6
- Exploitability score
- 3.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*", "vulnerable": true, "matchCriteriaId": "2D6B2329-5500-4D95-8270-2CCB839C226F", "versionEndExcluding": "16.5.8", "versionStartIncluding": "16.0.0" }, { "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "3732A61E-AFE9-4A84-B3A8-C34F0F79C5A0", "versionEndExcluding": "16.5.8", "versionStartIncluding": "16.0.0" }, { "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*", "vulnerable": true, "matchCriteriaId": "8429A44F-1788-421A-99A9-1E650735BBDD", "versionEndExcluding": "16.6.6", "versionStartIncluding": "16.6.0" }, { "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "3D66D64A-B883-4A2C-B114-3A54F326BA8D", "versionEndExcluding": "16.6.6", "versionStartIncluding": "16.6.0" }, { "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*", "vulnerable": true, "matchCriteriaId": "0F871342-EDE9-49F2-8081-04651A16CD6E", "versionEndExcluding": "16.7.4", "versionStartIncluding": "16.7.0" }, { "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "9A9ED476-FBE7-4022-AE16-18386E73AA59", "versionEndExcluding": "16.7.4", "versionStartIncluding": "16.7.0" }, { "criteria": "cpe:2.3:a:gitlab:gitlab:16.8.0:*:*:*:community:*:*:*", "vulnerable": true, "matchCriteriaId": "246D6584-64A7-44AC-A279-ECA58E5ED1FB" }, { "criteria": "cpe:2.3:a:gitlab:gitlab:16.8.0:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "E591D495-7397-4DA2-A643-477B2E35A915" } ], "operator": "OR" } ] } ]