CVE Vulnerabilities

CVE-2023-5332

Published: Dec 04, 2023 | Modified: Nov 21, 2024
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.1 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

Patch in third party library Consul requires enable-script-checks to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 9.5.0 (including) 16.2.8 (excluding)
Gitlab Gitlab 16.3.0 (including) 16.3.5 (excluding)
Gitlab Gitlab 16.4.0 (including) 16.4.0 (including)
Consul Ubuntu bionic *
Consul Ubuntu mantic *
Consul Ubuntu trusty *
Consul Ubuntu xenial *

References