8.1
CVSSv3

CVE-2023-5332

Published: 04/12/2023 Updated: 07/12/2023
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab

gitlab gitlab 16.4.0

hashicorp consul

hashicorp consul 1.1.0

Vendor Advisories

Description<!---->A command injection flaw was found in Hashicorp's Consul script check configuration option If the API is enabled and exposed through a public interface, it is possible to achieve remote code executionA command injection flaw was found in Hashicorp's Consul script check configuration option If the API is enabled and exposed thro ...