Weekly digest
Week 5, 2023 (30 Jan – 5 Feb)
A quiet week: only 3 new CVEs against a recent average of about 8. Of those, 1 high. No new KEV entries.
3
New CVEs
0
Critical
0
KEV additions
0
Records changed
New this week, ranked by depth score
The 3 that matter most of the 3 published.
CVE-2022-45786High· 8.1Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection
Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection
▾ Twilightapache · github.com/apache/age/drivers/golangEPSS 0.96%via OSV
CVE-2022-39324Medium· 6.7grafana: Spoofing of the originalUrl parameter of snapshots (CVE-2022-39324)
A flaw was found in the grafana package. While creating a snapshot, an attacker may manipulate a hidden HTTP parameter to inject a malicious URL in the "Open original dashboard" button.
▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.83%via CSAF
RUSTSEC-2023-0126NoneAliasing violation in `OrdSet` insertion
Aliasing violation in `OrdSet` insertion
▾ Sunlitim · imvia OSV
Most-affected vendors
By CVEs published in the period.