Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.
{
"severity": "High",
"cpes": [
"cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*",
"cpe:2.3:a:hashicorp:consul:1.1.0:*:*:*:-:*:*:*",
"cpe:2.3:a:hashicorp:consul:*:*:*:*:*:go:*:*"
]
}