CVE-2023-2030: Commit signature validation ignores headers after signature
An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-2030?
CVE-2023-2030 is a critical vulnerability that allows an attacker to modify the metadata of signed commits in GitLab.
How do I fix CVE-2023-2030?
To fix CVE-2023-2030, upgrade GitLab to version 16.5.6, 16.6.4, or 16.7.2 or later.
Which versions are affected by CVE-2023-2030?
CVE-2023-2030 affects all GitLab CE/EE versions from 12.2 up to, but not including, 16.5.6, 16.6 up to 16.6.4, and 16.7 up to 16.7.2.
What types of GitLab installations are impacted by CVE-2023-2030?
CVE-2023-2030 affects both GitLab Community Edition and Enterprise Edition installations.
Can CVE-2023-2030 be exploited remotely?
Yes, CVE-2023-2030 can be exploited remotely, allowing attackers to tamper with signed commit metadata.