CVE-2023-2030
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.
Summary dbcve.org
GitLab CE/EE versions 12.2 through 16.7.1 contain a flaw where an attacker could potentially modify the metadata of cryptographically signed commits. Signed commits rely on cryptographic signatures to verify author identity and commit integrity; this vulnerability allows metadata manipulation while potentially preserving the appearance of a valid signature, undermining the trust model of commit signing.
Mitigation
Upgrade GitLab to version 16.5.6, 16.6.4, or 16.7.2 or later. For systems on older major versions, plan a staged upgrade path to reach a patched release.