CVE-2024-2434

An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.
Configurations

No configuration.

History

21 Nov 2024, 09:09

Type Values Removed Values Added
References () https://gitlab.com/gitlab-org/gitlab/-/issues/450303 - () https://gitlab.com/gitlab-org/gitlab/-/issues/450303 -
References () https://hackerone.com/reports/2401952 - () https://hackerone.com/reports/2401952 -
Summary
  • (es) Se descubrió un problema en GitLab que afecta a todas las versiones de GitLab CE/EE 16.9 anteriores a 16.9.6, 16.10 anteriores a 16.10.4 y 16.11 anteriores a 16.11.1, donde el path traversal podría provocar DoS y lectura restringida de archivos.

25 Apr 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-25 11:15

Updated : 2024-11-21 09:09


NVD link : CVE-2024-2434

Mitre link : CVE-2024-2434

CVE.ORG link : CVE-2024-2434


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')