MEDIUM

CVE-2023-2030

Gitlab GitLab 2024-01-12 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.

Summary dbcve.org

GitLab CE/EE versions 12.2 through 16.7.1 contain a flaw where an attacker could potentially modify the metadata of cryptographically signed commits. Signed commits rely on cryptographic signatures to verify author identity and commit integrity; this vulnerability allows metadata manipulation while potentially preserving the appearance of a valid signature, undermining the trust model of commit signing.

Mitigation

Upgrade GitLab to version 16.5.6, 16.6.4, or 16.7.2 or later. For systems on older major versions, plan a staged upgrade path to reach a patched release.

Weakness (CWE)

CWE-347 Improper Signature Verification

EPSS Score

0.39%
Probability of exploitation in next 30 days
32.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE