Weekly digest
Week 11, 2023 (13–19 Mar)
8 new CVEs this week, in line with the recent average. Severity skewed high: 3 critical and 1 high, 50% of the total. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries.
New this week, ranked by depth score
The 8 that matter most of the 8 published.
CVE-2023-28461Critical· 9.8CISA KEVArray Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could…
CVE-2023-28531Critical· 9.8ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
CVE-2023-27582Critical· 9.1Full authentication bypass if SASL authorization username is specified
Full authentication bypass if SASL authorization username is specified
CVE-2023-1390High· 7.5A remote denial of service vulnerability was found in the Linux kernel’s TIPC kernel module
A remote denial of service vulnerability was found in the Linux kernel’s TIPC kernel module. The while loop in tipc_link_xmit() hits an unknown state while attempting to parse SKBs, which are not in the queue. Sending two small UDP packe…
CVE-2023-28607Medium· 6.1js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.
js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.
CVE-2023-28606Medium· 6.1js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.
js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.
CVE-2021-29456Medium· 5.4Authelia allows open redirects on the logout endpoint
Authelia allows open redirects on the logout endpoint
CVE-2023-27593Medium· 4.4cilium-agent container can access the host via `hostPath` mount
cilium-agent container can access the host via `hostPath` mount
Most-affected vendors
By CVEs published in the period.