Unrated severityNVD Advisory· Published Jan 12, 2024· Updated Nov 20, 2025
Improper Verification of Cryptographic Signature in GitLab
CVE-2023-2030
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.
Affected products
3- Range: >=12.2, <16.5.6; >=16.6, <16.6.4; >=16.7, <16.7.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- hackerone.com/reports/1929929mitretechnical-descriptionexploitpermissions-required
- gitlab.com/gitlab-org/gitlab/-/issues/407252mitreissue-tracking
News mentions
1- GitLab Critical Security Release: 16.7.2, 16.6.4, 16.5.6GitLab Security Releases · Jan 11, 2024