URGENT: Upgrade GitLab - Critical Workspace Creation Flaw Allows File Overwrite
ID: dae0d2d2-bb99-585f-9d89-ea88de056e19
STIX ID: report--dae0d2d2-bb99-585f-9d89-ea88de056e19
Feed Name: The Hacker News
Threat Score
GitLab released patches for a critical arbitrary-file-write vulnerability (CVE-2024-0402, CVSS 9.9) affecting multiple 16.x versions; authenticated users could write files to arbitrary locations when creating a workspace. Patches have been backported to several versions and users are urged to upgrade immediately; the advisory also mentions additional medium-severity issues and recent prior critical fixes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
