Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Michael Trainor

Pesquisador deGitLab
#22294de 56,335
12CVSS total
Vulnerabilidades · 2
Baixa
1
Alta
1
PT-2023-32051
8.1
2023-12-03
Hashicorp · Hashicorp Consul · CVE-2023-5332
**Name of the Vulnerable Software and Affected Versions** GitLab-EE (affected versions not specified) **Description** The issue is related to a patch in the third-party library Consul, which requires the 'enable-script-checks' setting to be set to False. This setting is necessary to enable a patch provided by the vendor. Without this setting, the patch could be bypassed. **Recommendations** To resolve the issue, set 'enable-script-checks' to False in the Consul library configuration. This change is required to ensure the patch is effective and cannot be bypassed. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2023-24415
3.9
2023-07-13
Gitlab · Gitlab Ce/Ee · CVE-2023-3363
**Name of the Vulnerable Software and Affected Versions** Gitlab CE/EE versions 13.6 through 15.11.10 Gitlab CE/EE versions 16.0 through 16.0.6 Gitlab CE/EE versions 16.1 through 16.1.1 **Description** An information disclosure issue resulted in the Sidekiq log including webhook tokens when the log format was set to `default`. **Recommendations** For versions 13.6 through 15.11.10, update to version 15.11.10 or later. For versions 16.0 through 16.0.6, update to version 16.0.6 or later. For versions 16.1 through 16.1.1, update to version 16.1.1 or later.