CVE-2023-6051

An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a specific tag.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

02 Jan 2024, 09:15

Type Values Removed Values Added
Summary (en) An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 15.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a specific tag. (en) An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a specific tag.

19 Dec 2023, 20:46

Type Values Removed Values Added
First Time Gitlab
Gitlab gitlab
CVSS v2 : unknown
v3 : 5.7
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
Summary
  • (es) Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones anteriores a 16.4.4, todas las versiones desde 15.5 anteriores a 16.5.4, todas las versiones desde 16.6 anteriores a 16.6.2. La integridad del archivo puede verse comprometida cuando el código fuente o los paquetes de instalación se extraen de una etiqueta específica.
References () https://gitlab.com/gitlab-org/gitlab/-/issues/431345 - () https://gitlab.com/gitlab-org/gitlab/-/issues/431345 - Broken Link
References () https://hackerone.com/reports/2237165 - () https://hackerone.com/reports/2237165 - Permissions Required

15 Dec 2023, 16:53

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-15 16:15

Updated : 2024-01-02 09:15


NVD link : CVE-2023-6051

Mitre link : CVE-2023-6051

CVE.ORG link : CVE-2023-6051


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')