Vulnerability Description
An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 12.2.0, < 16.5.6 |
Related Weaknesses (CWE)
References
- https://gitlab.com/gitlab-org/gitlab/-/issues/407252Issue TrackingVendor Advisory
- https://hackerone.com/reports/1929929Permissions Required
- https://gitlab.com/gitlab-org/gitlab/-/issues/407252Issue TrackingVendor Advisory
- https://hackerone.com/reports/1929929Permissions Required
FAQ
What is CVE-2023-2030?
CVE-2023-2030 is a vulnerability with a CVSS score of 3.5 (LOW). An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata...
How severe is CVE-2023-2030?
CVE-2023-2030 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-2030?
Check the references section above for vendor advisories and patch information. Affected products include: Gitlab Gitlab.