Gitlab · Gitlab Ce/Ee · CVE-2023-2030
**Name of the Vulnerable Software and Affected Versions**
GitLab CE/EE versions 12.2 through 16.5.5
GitLab CE/EE versions 16.6 through 16.6.3
GitLab CE/EE versions 16.7 through 16.7.1
**Description**
The issue is related to insufficient authentication of data in GitLab, allowing a remote attacker to modify the metadata of signed commits. This could potentially lead to unauthorized changes in the commit history.
**Recommendations**
For GitLab CE/EE versions 12.2 through 16.5.5, update to version 16.5.6 or later.
For GitLab CE/EE versions 16.6 through 16.6.3, update to version 16.6.4 or later.
For GitLab CE/EE versions 16.7 through 16.7.1, update to version 16.7.2 or later.