GitLab released security updates for Community Edition and Enterprise Edition to fix five vulnerabilities, including CVE-2024-0402, a critical arbitrary file write issue in workspace creation. The patched versions are 16.8.1, 16.7.4, 16.6.6, and 16.5.8, and GitLab urged customers to upgrade immediately. GitLab.com and GitLab Dedicated were already running remediated versions at the time of disclosure.
The same release also addressed four medium-severity flaws involving ReDoS, arbitrary API PUT requests through HTML injection, email disclosure in tags RSS feeds, and improper merge request assignee updates. GitLab additionally updated bundled components, including libxml2 2.12.3 to mitigate CVE-2023-45322 and Redis 7.0.15 to mitigate CVE-2023-41056, expanding the scope of the security release beyond the primary GitLab application flaws.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
On January 25, 2024, GitLab published security updates 16.8.1, 16.7.4, 16.6.6, and 16.5.8 for Community Edition and Enterprise Edition. The release fixed five vulnerabilities, including the critical arbitrary file write issue tracked as CVE-2024-0402, and GitLab urged customers to upgrade immediately.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.