VulnSea

Weekly digest

Week 14, 2023 (3–9 Apr)

8 new CVEs this week, in line with the recent average. Of those, 3 high. No new KEV entries.

8
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 8 that matter most of the 8 published.

CVE-2023-28710High· 7.5
3y ago

Apache Airflow Spark Provider vulnerable to improper input validation

Apache Airflow Spark Provider vulnerable to improper input validation

▾ Twilightapache-airflow-providers-apache-spark · apache-airflow-providers-apache-sparkEPSS 2.2%via OSV
CVE-2023-28707High· 7.5
3y ago

Apache Airflow Drill Provider vulnerable to improper input validation

Apache Airflow Drill Provider vulnerable to improper input validation

▾ Twilightapache-airflow-providers-apache-drill · apache-airflow-providers-apache-drillEPSS 2.1%via OSV
CVE-2023-28840High· 7.5
3y ago

Moby is an open source container framework developed by Docker Inc

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as m…

▾ Twilightmobyproject · mobyEPSS 2.6%via NVD
CVE-2023-28842Medium· 6.8
3y ago

moby: Encrypted overlay network with a single endpoint is unauthenticated (CVE-2023-28842)

A vulnerability was found in Moby due to an unprotected alternate channel within encrypted overlay networks, which could allow a remote attacker to bypass security restrictions. By sending a specially crafted request, an attacker could inj…

▾ SunlitRed Hat · multicluster engine for Kubernetes 2.4 for RHEL 8EPSS 1.4%via CSAF
CVE-2023-28841Medium· 6.8
3y ago

Moby is an open source container framework developed by Docker Inc

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as m…

▾ Sunlitmobyproject · mobyEPSS 0.69%via NVD
CVE-2023-28836Medium· 6.4
3y ago

Wagtail vulnerable to stored Cross-site Scripting attack via ModelAdmin views

Wagtail vulnerable to stored Cross-site Scripting attack via ModelAdmin views

▾ Sunlitwagtail · wagtailEPSS 0.78%via OSV
CVE-2023-28837Medium· 4.4
3y ago

Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large files

Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large files

▾ Sunlitwagtail · wagtailEPSS 1.1%via OSV
CVE-2023-26112Low· 3.7
3y ago

configobj ReDoS exploitable by developer using values in a server-side configuration file

configobj ReDoS exploitable by developer using values in a server-side configuration file

▾ Sunlitconfigobj · configobjEPSS 1.3%via OSV

Most-affected vendors

By CVEs published in the period.