Medium severity5.7NVD Advisory· Published Dec 15, 2023· Updated Jun 17, 2026
CVE-2023-6051
CVE-2023-6051
Description
An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a specific tag.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 0
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: <16.4.4
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: <16.4.4
- (no CPE)range: <16.4.4, >=16.5 <16.5.4, >=16.6 <16.6.2
- Range: <16.4.4, >=16.5 <16.5.4, >=16.6 <16.6.2
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/431345nvdBroken Link
- hackerone.com/reports/2237165nvdPermissions Required
News mentions
1- GitLab Security Release: 16.6.2, 16.5.4, 16.4.4GitLab Security Releases · Dec 13, 2023