CVE-2023-2030Improper Verification of Cryptographic Signature in Gitlab

Severity
5.3MEDIUMNVD
EPSS
0.0%
top 86.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages5 packages

CVEListV5gitlab/gitlab12.216.5.6+2
NVDgitlab/gitlab12.2.016.5.6+3
debiandebian/gitlab< gitlab 16.6.5-3 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-797c-p7mm-pf4h: An issue has been discovered in GitLab CE/EE affecting all versions from 122024-01-12
OSV
CVE-2023-2030: An issue has been discovered in GitLab CE/EE affecting all versions from 122024-01-12

💥Exploits & PoCs

1
Exploit-DB
Control Web Panel 7 (CWP7) v0.9.8.1147 - Remote Code Execution (RCE)2023-04-05

📋Vendor Advisories

2
GitLab
CVE-2023-2030: An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which2024-01-12
Debian
CVE-2023-2030: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 pr...2023

🕵️Threat Intelligence

1
Bleepingcomputer
GitLab warns of critical zero-click account hijacking vulnerability2024-01-12