An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Oct 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-345 |
Thu, 03 Oct 2024 06:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Insufficient Verification of Data Authenticity in GitLab | Improper Verification of Cryptographic Signature in GitLab |
Weaknesses | CWE-347 |
Thu, 29 Aug 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
MITRE
Status: PUBLISHED
Assigner: GitLab
Published: 2024-01-12T13:57:06.694Z
Updated: 2024-10-03T06:23:10.357Z
Reserved: 2023-04-13T18:20:57.328Z
Link: CVE-2023-2030
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2024-01-12T14:15:47.833
Modified: 2024-10-08T19:40:33.427
Link: CVE-2023-2030
Redhat
No data.