Vulnerability in GitLab allowing files to be written to arbitrary directories on the server

Corrective updates for the collaborative development platform have been released — GitLab 16.8.1, 16.7.4, 16.6.6, and 16.5.8, addressing 5 vulnerabilities. One of the issues (CVE-2024-0402), which has been present since the release of GitLab 16.0, has been assigned a critical severity level. This vulnerability allows an authenticated user to write files to any directory on the server, depending on the access rights of the GitLab web interface.

The vulnerability is caused by an error in the implementation of the workspace creation function. The error occurs when parsing devfile parameters specified in an incorrect YAML format (the patch resolves the issue by converting YAML to JSON and checking for constructs valid in YAML but not allowed in JSON due to the use of certain Unicode characters). Detailed information about the vulnerability is expected to be disclosed 30 days after the release of the fix. The vulnerability was identified during an internal audit by one of GitLab's employees.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster