Weekly digest
Week 2, 2023 (9–15 Jan)
10 new CVEs this week, in line with the recent average. Severity skewed high: 5 high, 50% of the total. No new KEV entries.
New this week, ranked by depth score
The 10 that matter most of the 10 published.
CVE-2023-22491High· 8.1Gatsby is a free and open source framework based on React that helps developers build websites and apps
Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 passes input through to the `gray-matter` npm package, which…
CVE-2023-0288High· 7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.
CVE-2022-4696High· 7.8There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation
There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current->nsproxy, s…
CVE-2022-41721High· 7.5x/net/http2/h2c: request smuggling (CVE-2022-41721)
A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead read the b…
CVE-2022-4885High· 7.5sviehb/jefferson vulnerable to path traversal
sviehb/jefferson vulnerable to path traversal
CVE-2023-0227Medium· 6.5Pyload Insufficient Session Expiration vulnerability
Pyload Insufficient Session Expiration vulnerability
CVE-2023-22492Medium· 5.9Zitadel RefreshToken invalidation vulnerability
Zitadel RefreshToken invalidation vulnerability
CVE-2022-2196Medium· 5.8A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) adv…
A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) adv…
CVE-2023-20008Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or …
CVE-2023-20002Medium· 4.4Cisco TelePresence CE and RoomOS Software Server-Side Request Forgery Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or …
Most-affected vendors
By CVEs published in the period.