Unrated severityNVD Advisory· Published Dec 4, 2023· Updated Oct 3, 2024
Dependency on Vulnerable Third-Party Component in GitLab
CVE-2023-5332
Description
Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.
Affected products
3- osv-coords2 versions
< 0.9.4+ 1 more
- (no CPE)range: < 0.9.4
- (no CPE)range: >= 9.5.0, < 16.2.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
1- GitLab Security Release: 16.4.1, 16.3.5, and 16.2.8GitLab Security Releases · Sep 28, 2023