An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.
2024-01-12T14:15:47.833
2025-03-20T17:00:53.620
Analyzed
CVSSv3.1: 3.5 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 16.5.6 | Yes |
Application | gitlab | gitlab | < 16.5.6 | Yes |
Application | gitlab | gitlab | < 16.6.4 | Yes |
Application | gitlab | gitlab | < 16.6.4 | Yes |
Application | gitlab | gitlab | 16.7.0 | Yes |
Application | gitlab | gitlab | 16.7.0 | Yes |
Application | gitlab | gitlab | 16.7.1 | Yes |
Application | gitlab | gitlab | 16.7.1 | Yes |