GitLab users warned of flaw that allows file overwrite — so update now
GitLab recently discovered a critical vulnerability in its Community Edition (CE) and Enterprise Edition (EE) instances, which could allow malicious actors to write arbitrary files while creating a workspace.
In a security bulletin, GitLab said the vulnerability is quite serious and that users should apply the patch with utmost urgency.
The vulnerability affects all versions from 16.0 prior to 16.5.8, 16.6 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1, the project said in the announcement.
More bugs to patch
“This is a critical severity issue,” GitLab said, adding that it has been assigned a severity score of 9.9. “It is now mitigated in the latest release and is assigned CVE-2024-0402.”
The company also said the patch was backported to 16.5.8 besides 16.6.6, 16.7.4, and 16.8.1. “GitLab 16.5.8 only includes a fix for this vulnerability and does not contain any of the other fixes or changes mentioned in this blog post,” the announcement concluded. GitLab.com and GitLab Dedicated environments are said to already be running the upgraded version.
In the same advisory, GitLab also said it addressed four medium-severity flaws that could result in a regular expression denial-of-service (ReDoS), HTML injection, and the leaking of users’ public email addresses via the tags RSS feed.
This is not the first time GitLab users were urged to immediately apply a patch and fix a critical flaw. In September last year, GitLab said it found a flaw in scan execution policies to run pipelines (a series of automated tasks) as another user.
This flaw was tracked as CVE-2023-4998 and carries a severity score of 9.6. It impacted a couple of versions of the software, namely GitLab Community Edition (CE) and Enterprise Edition (EE) versions 13.12 through 16.2.7, and versions 16.3 through 16.3.4.
Via The Hacker News
More from TechRadar Pro
GitLab recently discovered a critical vulnerability in its Community Edition (CE) and Enterprise Edition (EE) instances, which could allow malicious actors to write arbitrary files while creating a workspace. In a security bulletin, GitLab said the vulnerability is quite serious and that users should apply the patch with utmost urgency.…
Recent Posts
- Is the Steam Deck still worth it in 2026?
- This little robot window-cleaner is the best labor-saving device I’ve ever used, and it’s going cheap at Amazon right now
- Grab Kodak’s best-selling compact camera from the past two years for less, with a 30% discount this Labor Day
- Explore the globe in field recordings
- iPhone Handoff will seamlessly share one number between two phones
Archives
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023