VulnerabilityAnalyzed
CVE-2023-2030
An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.
MEDIUM 5.3EPSS 0.39%
Does this matter?
Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.39% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-347
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/gitlab/-/issues/407252Issue Tracking, Vendor Advisory
- https://hackerone.com/reports/1929929Permissions Required
- https://gitlab.com/gitlab-org/gitlab/-/issues/407252Issue Tracking, Vendor Advisory
- https://hackerone.com/reports/1929929Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.