Low severity2.6NVD Advisory· Published Jun 7, 2023· Updated Jun 17, 2026
CVE-2023-2013
CVE-2023-2013
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 1.2 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=1.2.0,<15.10.8
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=1.2.0,<15.10.8
- (no CPE)range: 1.2 - 15.10.8, 15.11 - 15.11.7, 16.0 - 16.0.2
- (no CPE)range: >=1.2, <15.10.8
- Range: 1.2 - 15.10.8, 15.11 - 15.11.7, 16.0 - 16.0.2
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2013.jsonnvdVendor Advisory
- hackerone.com/reports/1940441nvdPermissions RequiredThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/406844nvdBroken Link
News mentions
1- GitLab Security Release: 16.0.2, 15.11.7, and 15.10.8GitLab Security Releases · Jun 5, 2023