An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-33557 | An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits. |
Fixes
Solution
Upgrade to versions 16.5.6, 16.6.4, 16.7.2 or above.
Workaround
No workaround given by the vendor.
References
History
Tue, 17 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Oct 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-345 |
Thu, 03 Oct 2024 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insufficient Verification of Data Authenticity in GitLab | Improper Verification of Cryptographic Signature in GitLab |
| Weaknesses | CWE-347 |
Thu, 29 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-06-17T21:09:16.695Z
Reserved: 2023-04-13T18:20:57.328Z
Link: CVE-2023-2030
Updated: 2025-06-17T21:07:05.798Z
Status : Analyzed
Published: 2024-01-12T14:15:47.833
Modified: 2025-03-20T17:00:53.620
Link: CVE-2023-2030
No data.
OpenCVE Enrichment
No data.
EUVD