CVE-2024-2434
HIGHGitLab CE/EE <16.9.6-16.11.1 - Path Traversal
Title source: llmDescription
An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.
Scores
CVSS v3
8.5
EPSS
0.0369
EPSS Percentile
87.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H
Classification
CWE
CWE-22
Status
published
Affected Products (4)
gitlab/gitlab
< 16.9.6
gitlab/gitlab
< 16.9.6
gitlab/gitlab
gitlab/gitlab
Timeline
Published
Apr 25, 2024
Tracked Since
Feb 18, 2026