Critical severity9.9NVD Advisory· Published Jan 26, 2024· Updated Jun 17, 2026
CVE-2024-0402
CVE-2024-0402
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 16.0
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=16.0.0,<16.5.8
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=16.0.0,<16.5.8
- cpe:2.3:a:gitlab:gitlab:16.8.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:16.8.0:*:*:*:enterprise:*:*:*
- Range: from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1
Patches
Vulnerability mechanics
References
2News mentions
1- GitLab Critical Security Release: 16.8.1, 16.7.4, 16.6.6, 16.5.8GitLab Security Releases · Jan 25, 2024