CVE-2024-2434: GitLab

High severity, CVSS 8.1. EPSS: 23.2% chance of exploitation in the next 30 days.

An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.

Affected products

  • GitLab GitLab: from 16.9.0, before 16.9.6 (fixed in 16.9.6); from 16.10.0, before 16.10.4 (fixed in 16.10.4); version 16.11.0 only

Published 2024-04-25. Last modified 2026-06-17.