VYPR
Medium severity5.9NVD Advisory· Published Dec 4, 2023· Updated Jun 17, 2026

CVE-2023-5332

CVE-2023-5332

Description

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • GitLab Inc./GitLabv53 versions
    cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 9.5.0
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=9.5.0,<16.2.8
    • cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*
  • Hashicorp/Consul2 versions
    cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*+ 1 more
    • cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*range: <0.9.4
    • cpe:2.3:a:hashicorp:consul:1.1.0:*:*:*:-:*:*:*
  • osv-coords2 versions
    < 0.9.4+ 1 more
    • (no CPE)range: < 0.9.4
    • (no CPE)range: >= 9.5.0, < 16.2.8

Patches

Vulnerability mechanics

References

2

News mentions

1