VYPR
Unrated severityNVD Advisory· Published Apr 25, 2024· Updated Nov 20, 2025

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab

CVE-2024-2434

Description

An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

1