Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-0402

Опубликовано: 26 янв. 2024
Источник: ubuntu
Приоритет: medium
CVSS3: 9.9

Описание

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-apps-legacy/xenial

ignored

not maintainable
esm-apps/xenial

ignored

end of ESM support, was ignored [not maintainable]
esm-infra/focal

DNE

focal

DNE

jammy

DNE

lunar

DNE

mantic

DNE

noble

DNE

Показывать по

9.9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.9
nvd
больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

CVSS3: 9.9
debian
больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 9.9
github
больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

CVSS3: 9.9
fstec
больше 2 лет назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю выполнить запись файла в произвольные места на сервере при создании рабочей области

9.9 Critical

CVSS3