PT-2023-32051 · Hashicorp+2 · Hashicorp Consul+2

Michael Trainor

·

Published

2023-12-03

·

Updated

2024-10-03

·

CVE-2023-5332

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitLab-EE (affected versions not specified)
Description The issue is related to a patch in the third-party library Consul, which requires the 'enable-script-checks' setting to be set to False. This setting is necessary to enable a patch provided by the vendor. Without this setting, the patch could be bypassed.
Recommendations To resolve the issue, set 'enable-script-checks' to False in the Consul library configuration. This change is required to ensure the patch is effective and cannot be bypassed. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BIT-CONSUL-2023-5332
BIT-GITLAB-2023-5332
CVE-2023-5332

Affected Products

Hashicorp Consul
Debian
Gitlab