PT-2023-32051 · Hashicorp+2 · Hashicorp Consul+2

Michael Trainor

·

Publicado

2023-12-03

·

Atualizado

2024-10-03

·

CVE-2023-5332

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitLab-EE (affected versions not specified)
Description The issue is related to a patch in the third-party library Consul, which requires the 'enable-script-checks' setting to be set to False. This setting is necessary to enable a patch provided by the vendor. Without this setting, the patch could be bypassed.
Recommendations To resolve the issue, set 'enable-script-checks' to False in the Consul library configuration. This change is required to ensure the patch is effective and cannot be bypassed. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-CONSUL-2023-5332
BIT-GITLAB-2023-5332
CVE-2023-5332

Produtos afetados

Hashicorp Consul
Debian
Gitlab