CVE-2023-5332
04.12.2023, 07:15
Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.Enginsight
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 9.5.0 ≤ 𝑥 < 16.2.8 |
gitlab | gitlab | 16.3.0 ≤ 𝑥 < 16.3.5 |
gitlab | gitlab | 16.4.0 |
hashicorp | consul | 𝑥 < 0.9.4 |
hashicorp | consul | 1.0.0 ≤ 𝑥 < 1.0.8 |
hashicorp | consul | 1.2.0 ≤ 𝑥 < 1.2.4 |
hashicorp | consul | 1.1.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References