Weekly digest
Week 14, 2023 (3–9 Apr)
8 new CVEs this week, in line with the recent average. Of those, 3 high. No new KEV entries.
New this week, ranked by depth score
The 8 that matter most of the 8 published.
CVE-2023-28710High· 7.5Apache Airflow Spark Provider vulnerable to improper input validation
Apache Airflow Spark Provider vulnerable to improper input validation
CVE-2023-28707High· 7.5Apache Airflow Drill Provider vulnerable to improper input validation
Apache Airflow Drill Provider vulnerable to improper input validation
CVE-2023-28840High· 7.5Moby is an open source container framework developed by Docker Inc
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as m…
CVE-2023-28842Medium· 6.8moby: Encrypted overlay network with a single endpoint is unauthenticated (CVE-2023-28842)
A vulnerability was found in Moby due to an unprotected alternate channel within encrypted overlay networks, which could allow a remote attacker to bypass security restrictions. By sending a specially crafted request, an attacker could inj…
CVE-2023-28841Medium· 6.8Moby is an open source container framework developed by Docker Inc
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as m…
CVE-2023-28836Medium· 6.4Wagtail vulnerable to stored Cross-site Scripting attack via ModelAdmin views
Wagtail vulnerable to stored Cross-site Scripting attack via ModelAdmin views
CVE-2023-28837Medium· 4.4Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large files
Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large files
CVE-2023-26112Low· 3.7configobj ReDoS exploitable by developer using values in a server-side configuration file
configobj ReDoS exploitable by developer using values in a server-side configuration file
Most-affected vendors
By CVEs published in the period.