logo

URGENT: Upgrade GitLab - Critical Workspace Creation Flaw Allows File Overwrite

ID: dae0d2d2-bb99-585f-9d89-ea88de056e19

STIX ID: report--dae0d2d2-bb99-585f-9d89-ea88de056e19

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-01-30

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

GitLab released patches for a critical arbitrary-file-write vulnerability (CVE-2024-0402, CVSS 9.9) affecting multiple 16.x versions; authenticated users could write files to arbitrary locations when creating a workspace. Patches have been backported to several versions and users are urged to upgrade immediately; the advisory also mentions additional medium-severity issues and recent prior critical fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.