Low severity3.5NVD Advisory· Published Jan 12, 2024· Updated Jun 17, 2026
CVE-2023-2030
CVE-2023-2030
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.
Affected products
9cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 12.2
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=12.2.0,<16.5.6
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=12.2.0,<16.5.6
- cpe:2.3:a:gitlab:gitlab:16.7.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:16.7.0:*:*:*:enterprise:*:*:*
- cpe:2.3:a:gitlab:gitlab:16.7.1:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:16.7.1:*:*:*:enterprise:*:*:*
- Range: from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/407252nvdIssue TrackingVendor Advisory
- hackerone.com/reports/1929929nvdPermissions Required
News mentions
1- GitLab Critical Security Release: 16.7.2, 16.6.4, 16.5.6GitLab Security Releases · Jan 11, 2024