Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/5xxx/CVE-2023-5332.json",
"cna_assigner": "GitLab",
"cwe_ids": [
"CWE-1395"
]
}{
"versions": [
{
"introduced": "0"
},
{
"fixed": "0.9.4"
},
{
"introduced": "1.0.0"
},
{
"fixed": "1.0.8"
},
{
"introduced": "1.2.0"
},
{
"fixed": "1.2.4"
}
]
}{
"versions": [
{
"introduced": "9.5.0"
},
{
"fixed": "16.2.8"
},
{
"introduced": "16.3.0"
},
{
"fixed": "16.3.5"
},
{
"introduced": "0"
},
{
"last_affected": "16.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.1.0"
}
]
}