Weekly digest
Week 23, 2023 (5–11 Jun)
10 new CVEs this week, in line with the recent average. Severity skewed high: 1 critical and 7 high, 80% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. rancher was the most-affected vendor with 3.
New this week, ranked by depth score
The 10 that matter most of the 10 published.
CVE-2023-33977High· 8.1PoCkiwitcms vulnerable to stored cross-site scripting via unrestricted file upload
kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload
CVE-2023-22647Critical· 9.9Rancher vulnerable to Privilege Escalation via manipulation of Secrets
Rancher vulnerable to Privilege Escalation via manipulation of Secrets
CVE-2023-33733High· 7.8PoCReportlab vulnerable to remote code execution
Reportlab vulnerable to remote code execution
CVE-2020-10676High· 8.8Rancher users retain access after moving namespaces into projects they don't have access to
Rancher users retain access after moving namespaces into projects they don't have access to
CVE-2022-43760High· 8.4Rancher UI has multiple Cross-Site Scripting (XSS) issues
Rancher UI has multiple Cross-Site Scripting (XSS) issues
CVE-2023-33967High· 8.2SQL injection when using MySQL/PostgreSQL data checking
SQL injection when using MySQL/PostgreSQL data checking
CVE-2023-2801High· 7.5Grafana Missing Synchronization vulnerability
Grafana Missing Synchronization vulnerability
CVE-2023-34239High· 7.3Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
CVE-2023-34091Medium· 6.5Kyverno resource with a deletionTimestamp may allow policy circumvention
Kyverno resource with a deletionTimestamp may allow policy circumvention
CVE-2023-32682Medium· 5.4Synapse has improper checks for deactivated users during login
Synapse has improper checks for deactivated users during login
Most-affected vendors
By CVEs published in the period.