CVE-2023-6051
Description
An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a specific tag.
Summary dbcve.org
In GitLab CE/EE, file integrity can be compromised when pulling source code or installation packages from a specific tag. The vulnerability affects multiple version ranges before the fixed releases (16.4.4, 16.5.4, and 16.6.2), suggesting an issue with how GitLab handles tag-based operations for code/package retrieval.
Mitigation
Upgrade GitLab to version 16.4.4 or later, 16.5.4 or later, or 16.6.2 or later depending on your current branch. Alternatively, avoid pulling source code or installation packages from tags until the upgrade is completed.