5.3

CVE-2023-2030

Improper Verification of Cryptographic Signature in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab SwEdition community Version >= 12.2.0 < 16.5.6
Gitlab ≫ GitLab SwEdition enterprise Version >= 12.2.0 < 16.5.6
Gitlab ≫ GitLab SwEdition community Version >= 16.6.0 < 16.6.4
Gitlab ≫ GitLab SwEdition enterprise Version >= 16.6.0 < 16.6.4
Gitlab ≫ GitLab Version 16.7.0 SwEdition community
Gitlab ≫ GitLab Version 16.7.0 SwEdition enterprise
Gitlab ≫ GitLab Version 16.7.1 SwEdition community
Gitlab ≫ GitLab Version 16.7.1 SwEdition enterprise
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.3
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
cve@gitlab.com 3.5 2.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

https://gitlab.com/gitlab-org/gitlab/-/issues/407252
Vendor Advisory
Issue Tracking
https://hackerone.com/reports/1929929
Permissions Required