Weekly digest
Week 50, 2022 (12–18 Dec)
8 new CVEs this week, in line with the recent average. Severity skewed high: 4 high, 50% of the total. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. Red Hat was the most-affected vendor with 3.
New this week, ranked by depth score
The 8 that matter most of the 8 published.
CVE-2022-4223High· 8.8PoCpgadmin4 vulnerable to Code Injection
pgadmin4 vulnerable to Code Injection
CVE-2022-23526High· 7.5⚖ disputedhelm: Denial of service through schema file (CVE-2022-23526)
A flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_chartutil_ package that could cause a segmentation violation. The _chartut…
CVE-2022-23525High· 7.5⚖ disputedhelm: Denial of service through through repository index file (CVE-2022-23525)
A flaw was found in Helm. Applications that use the _repo_ package in Helm SDK to parse an index file may suffer a denial of service when that input causes a panic that cannot be recovered from. The Helm Client will panic with an index fil…
CVE-2022-23524High· 7.5⚖ disputedhelm: Denial of service through string value parsing (CVE-2022-23524)
A flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption. Input to functions in the _strvals_ package could cause a stack overflo…
CVE-2022-42343Medium· 6.5Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read
Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the app…
CVE-2022-4589Medium· 6.1Terms and Conditions Module vulnerable to Open Redirect
Terms and Conditions Module vulnerable to Open Redirect
CVE-2022-4312Medium· 5.5A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3
A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files to disco…
CVE-2022-4311Medium· 4.7An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2
An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConne…
Most-affected vendors
By CVEs published in the period.