iTnews Asia
  • Home
  • News
  • Security

GitLab patches another critical vulnerability

GitLab patches another critical vulnerability

Plus four medium-rated bugs.

By Richard Chirgwin on Jan 30, 2024 11:06AM

Popular source code management platform GitLab was patched on Friday, Australian time, against five vulnerabilities, including one with a critical severity rating.

The patches apply to both the enterprise and the community editions of GitLab.

The critical vulnerability is CVE-2024-0402 and carries a CVSS score of 9.9.

Discovered by GitLab employee Joern Schneeweisz, the bug “allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace”.

This means an attacker could exploit the vulnerability to distribute malware as well as to steal data.

It affects “all versions from 16.0 prior to 16.5.8, 16.6 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1”, GitLab said in its advisory, with the vulnerability fixed in version 16.8.1; the fix has also been backported to version 16.5.8.

Earlier this month, GitLab addressed a critical account takeover bug.

The four medium-rated vulnerabilities fixed in last week’s release are:

  • CVE-2023-6159 – A denial-of-service triggered by a malicious regular expression in a Cargo manifest;
  • CVE-2023-5933 – Improper input sanitization of username allows arbitrary API PUT requests;
  • CVE-2023-5612 – Disclosure of user emails via the Tags RSS feed; and
  • CVE-2024-0456 – An unauthorised attacker can assign any user to merge requests in a project.

Two third-party packages, the libxml2 library and redis, have also been patched against vulnerabilities.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
gitlab security

Related Articles

  • Sophos: Identity attacks have overtaken software flaws as entry point of ransomware
  • Strategies to mitigate against the real world impact of identity attacks
  • How can the Agentic AI workspace remain secure for APAC organisations?
  • AI-fuelled attacks forcing enterprises to rethink security architecture
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

How can the Agentic AI workspace remain secure for APAC organisations?

How can the Agentic AI workspace remain secure for APAC organisations?

Strategies to mitigate against the real world impact of identity attacks

Strategies to mitigate against the real world impact of identity attacks

Sophos: Identity attacks have overtaken software flaws as entry point of ransomware

Sophos: Identity attacks have overtaken software flaws as entry point of ransomware

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.