← Back to browse · API

CVE-2024-0402

Severity
CRITICAL
CVSS
9.9
EPSS
0.03783
Risk score
40.92
CISA KEV
No
PoC
No
Published
2024-01-26
Modified
2026-06-03
First seen
2026-08-07
Aliases
EUVD-2024-16198, GHSA-3HM6-RVRR-HC6R
Products
GitLab:GitLab 16.0 <16.5.8, GitLab:GitLab 16.6 <16.6.6, GitLab:GitLab 16.7 <16.7.4, GitLab:GitLab 16.8 <16.8.1
Sources
euvd EUVD-2024-16198

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

References