An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.
Solution:
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/407252 | vendor advisory issue tracking |
https://hackerone.com/reports/1929929 | broken link exploit permissions required technical description |