PT-2024-1047 · Gitlab · Gitlab Ce/Ee+1

Lotsofloops

·

Published

2024-01-11

·

Updated

2025-03-20

·

CVE-2023-2030

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 12.2 through 16.5.5 GitLab CE/EE versions 16.6 through 16.6.3 GitLab CE/EE versions 16.7 through 16.7.1
Description The issue is related to insufficient authentication of data in GitLab, allowing a remote attacker to modify the metadata of signed commits. This could potentially lead to unauthorized changes in the commit history.
Recommendations For GitLab CE/EE versions 12.2 through 16.5.5, update to version 16.5.6 or later. For GitLab CE/EE versions 16.6 through 16.6.3, update to version 16.6.4 or later. For GitLab CE/EE versions 16.7 through 16.7.1, update to version 16.7.2 or later.

Exploit

Fix

Insufficient Verification of Data Authenticity

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00261
BIT-GITLAB-2023-2030
CVE-2023-2030

Affected Products

Gitlab
Gitlab Ce/Ee