Weekly digest
Week 21, 2023 (22–28 May)
8 new CVEs this week, in line with the recent average. Of those, 1 critical and 1 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries.
8
New CVEs
1
Critical
0
KEV additions
0
Records changed
New this week, ranked by depth score
The 8 that matter most of the 8 published.
CVE-2023-32321Critical· 9.8Ckan remote code execution and private information access via crafted resource ids
Ckan remote code execution and private information access via crafted resource ids
▾ Midnightckan · ckanEPSS 1.7%via OSV
CVE-2023-32681Medium· 6.1PoCUnintended leak of Proxy-Authorization header in requests
Unintended leak of Proxy-Authorization header in requests
▾ Twilightrequests · requestsEPSS 3.0%via OSV
CVE-2023-32698High· 7.1nfpm has incorrect default permissions
nfpm has incorrect default permissions
▾ Twilightgoreleaser · github.com/goreleaser/nfpm/v2EPSS 0.38%via OSV
CVE-2021-25748Medium· 6.5Ingress-nginx `path` sanitization can be bypassed with newline character
Ingress-nginx `path` sanitization can be bypassed with newline character
▾ Sunlitingress-nginx · k8s.io/ingress-nginxEPSS 0.69%via OSV
CVE-2023-32686Medium· 5.4kiwitcms vulnerable to stored XSS via unrestricted files upload
kiwitcms vulnerable to stored XSS via unrestricted files upload
▾ Sunlitkiwitcms · kiwitcmsEPSS 0.43%via OSV
CVE-2023-30851Medium· 5.3Potential HTTP policy bypass when using header rules in Cilium
Potential HTTP policy bypass when using header rules in Cilium
▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.66%via OSV
CVE-2023-33191Medium· 4.6kyverno seccomp control can be circumvented
kyverno seccomp control can be circumvented
▾ Sunlitkyverno · github.com/kyverno/kyvernoEPSS 0.48%via OSV
CVE-2023-33185Medium· 4.6Incorrect signature verification in django-ses
Incorrect signature verification in django-ses
▾ Sunlitdjango-ses · django-sesEPSS 0.23%via OSV
Most-affected vendors
By CVEs published in the period.