iTnews Asia
  • Home
  • News
  • Security

GitLab patches another critical vulnerability

GitLab patches another critical vulnerability

Plus four medium-rated bugs.

By Richard Chirgwin on Jan 30, 2024 11:06AM

Popular source code management platform GitLab was patched on Friday, Australian time, against five vulnerabilities, including one with a critical severity rating.

The patches apply to both the enterprise and the community editions of GitLab.

The critical vulnerability is CVE-2024-0402 and carries a CVSS score of 9.9.

Discovered by GitLab employee Joern Schneeweisz, the bug “allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace”.

This means an attacker could exploit the vulnerability to distribute malware as well as to steal data.

It affects “all versions from 16.0 prior to 16.5.8, 16.6 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1”, GitLab said in its advisory, with the vulnerability fixed in version 16.8.1; the fix has also been backported to version 16.5.8.

Earlier this month, GitLab addressed a critical account takeover bug.

The four medium-rated vulnerabilities fixed in last week’s release are:

  • CVE-2023-6159 – A denial-of-service triggered by a malicious regular expression in a Cargo manifest;
  • CVE-2023-5933 – Improper input sanitization of username allows arbitrary API PUT requests;
  • CVE-2023-5612 – Disclosure of user emails via the Tags RSS feed; and
  • CVE-2024-0456 – An unauthorised attacker can assign any user to merge requests in a project.

Two third-party packages, the libxml2 library and redis, have also been patched against vulnerabilities.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
gitlab security

Related Articles

  • The best way to outsmart your threat actors is to think like one
  • How cybercriminals are exploiting LLMs to harm your business
  • Is identity now the next parameter of cybersecurity breaches?
  • Cybersecurity threats CISOs should be most worried about in 2025
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

The best way to outsmart your threat actors is to think like one

The best way to outsmart your threat actors is to think like one

What are the most pressing cyber security concerns going into 2025?

What are the most pressing cyber security concerns going into 2025?

Malaysia ramps up cyber security defense to stem rising fraud and ransomware attacks

Malaysia ramps up cyber security defense to stem rising fraud and ransomware attacks

How cybercriminals are exploiting LLMs to harm your business

How cybercriminals are exploiting LLMs to harm your business

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.