Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-5332

Опубликовано: 04 дек. 2023
Источник: debian
EPSS Низкий

Описание

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
consulremovedpackage
consulno-dsabullseyepackage
consulno-dsabusterpackage

Примечания

  • https://gitlab.com/gitlab-org/omnibus-gitlab/-/issues/8171

  • https://www.hashicorp.com/blog/protecting-consul-from-rce-risk-in-specific-configurations

EPSS

Процентиль: 4%
0.00021
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 1 года назад

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 8.1
redhat
больше 1 года назад

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 5.9
nvd
больше 1 года назад

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVSS3: 5.9
github
больше 1 года назад

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

EPSS

Процентиль: 4%
0.00021
Низкий