Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.
2023-12-04T07:15:07.120
2024-11-21T08:41:33.020
Modified
CVSSv3.1: 5.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 16.2.8 | Yes |
Application | gitlab | gitlab | < 16.3.5 | Yes |
Application | gitlab | gitlab | 16.4.0 | Yes |
Application | hashicorp | consul | < 0.9.4 | Yes |
Application | hashicorp | consul | < 1.0.8 | Yes |
Application | hashicorp | consul | < 1.2.4 | Yes |
Application | hashicorp | consul | 1.1.0 | Yes |