Open Nav
Sign Up

Critical File Overwrite Vulnerability in GitLab (CVE-2024-0402)

Bar Refael

January 31, 2024

GitLab has issued a critical security update for its Community Edition (CE) and Enterprise Edition (EE) to address a vulnerability identified as CVE-2024-0402, carrying a high CVSS score of 9.9. The flaw enables authenticated users to write arbitrary files to any location on the GitLab server while creating a workspace, posing significant security risks. In addition to this major vulnerability, GitLab also resolved four medium-severity flaws related to denial-of-service, HTML injection, and private information disclosure.

Affected Versions:

The vulnerability affects all versions of GitLab CE/EE:

  • From 16.0 up to but not including 16.5.8
  • From 16.6 up to but not including 16.6.6
  • From 16.7 up to but not including 16.7.4
  • From 16.8 up to but not including 16.8.1

Technical Details and Impact:

CVE-2024-0402 allows an authenticated user to exploit the workspace creation process to write files to arbitrary locations on the GitLab server. This critical vulnerability can lead to unauthorized data modification, data destruction, or give attackers a foothold for further malicious activities within the network.

The medium-severity vulnerabilities addressed include:

  • Regular expression denial-of-service (ReDoS)
  • HTML injection
  • Disclosure of a user’s public email address via tags RSS feed

Mitigation and Recommendations:

GitLab urges all users to upgrade their installations to the latest patched versions (16.5.8, 16.6.6, 16.7.4, or 16.8.1) immediately to mitigate potential risks. The patches have been backported to these versions to ensure security across the board. It is crucial for administrators to apply these updates as soon as possible to secure their environments against potential exploitation.

Conclusion:

The discovery of the critical file overwrite vulnerability, along with the other medium-severity flaws in GitLab, demands immediate attention and action from all GitLab users. The severity of CVE-2024-0402, coupled with the possibility of account takeover from other vulnerabilities like CVE-2023-7028, illustrates the urgency of updating to the latest, secured versions of GitLab. Continuous vigilance and prompt application of security updates are paramount in maintaining a robust defense against evolving cybersecurity threats.

Resources highlights

Next.js Critical Vulnerabilities Enable Unauthenticated RCE

Vercel has released security updates for two critical vulnerabilities in Next.js that could allow unauthenticated attackers to achieve remote code execution on vulnerable applications. The…

Read more >

next.js

Keycloak CVE-2026-18963 Enables Unauthenticated Account Takeover

A critical vulnerability in Keycloak could allow an unauthenticated remote attacker to take control of arbitrary user accounts through the platform's password recovery functionality. Tracked…

Read more >

cve-2026-18963

Elementor Pro CVE-2026-32475 Enables Unauthenticated File Upload and RCE

A critical vulnerability in the widely deployed Elementor Pro plugin for WordPress can allow unauthenticated attackers to bypass file-type restrictions, upload executable PHP files to…

Read more >

CVE-2026-32475

Windows IKE CVE-2026-33824 Exploited for Pre-Auth Remote Code Execution

A critical remote code execution vulnerability in Microsoft Windows Internet Key Exchange (IKE) is now being actively exploited. Tracked as CVE-2026-33824, the vulnerability is a…

Read more >

cve-2026-33824

VMware vCenter CVE-2026-59310 Actively Exploited for RCE and Persistent Access

Threat actors are actively exploiting CVE-2026-59310, a critical unauthenticated remote code execution vulnerability affecting VMware vCenter Server, with incident responders identifying compromises across dozens of…

Read more >

cve-2026-59310

ShieldBreak: Microsoft Defender 0-Day Leads to SYSTEM Privileges

A security researcher has released ShieldBreak, a new proof-of-concept exploit targeting Microsoft Defender that can elevate a low-privileged Windows user to NT AUTHORITY\SYSTEM on fully…

Read more >

shieldbreak
Under Cyber Attack?

Fill out the form and we will contact you immediately.