CVE-2023-5332: GitLab
High severity, CVSS 8.1. EPSS: 0.9% chance of exploitation in the next 30 days.
Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.
Affected products
- GitLab GitLab: from 9.5.0, before 16.2.8 (fixed in 16.2.8); from 16.3.0, before 16.3.5 (fixed in 16.3.5); version 16.4.0 only
- Hashicorp Consul: before 0.9.4 (fixed in 0.9.4); from 1.0.0, before 1.0.8 (fixed in 1.0.8); from 1.2.0, before 1.2.4 (fixed in 1.2.4); version 1.1.0 only
Published 2023-12-04. Last modified 2026-06-17.