Weekly digest
Week 32, 2023 (7–13 Aug)
A busier-than-usual week with 14 new CVEs (recent average about 10). Severity skewed high: 9 high, 64% of the total. No new KEV entries.
New this week, ranked by depth score
The 12 that matter most of the 14 published.
CVE-2023-39363High· 8.7Vyper has incorrectly allocated named re-entrancy locks
Vyper has incorrectly allocated named re-entrancy locks
CVE-2023-39349High· 8.1Privilege escalation via ApiTokensEndpoint
Privilege escalation via ApiTokensEndpoint
CVE-2023-39553High· 7.5apache-airflow-providers-apache-drill Improper Input Validation vulnerability
apache-airflow-providers-apache-drill Improper Input Validation vulnerability
CVE-2023-39533High· 7.5go-libp2p is the Go implementation of the libp2p Networking Stack
go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.8, 0.28.2, and 0.29.1 malicious peer can use large RSA keys to run a resource exhaustion attack & force a node to spend time doing signature verifi…
CVE-2020-35141High· 7.5FaucetSDN Ryu Denial of Service Vulnerability
FaucetSDN Ryu Denial of Service Vulnerability
CVE-2020-35139High· 7.5FaucetSDN Ryu Denial of Service Vulnerability
FaucetSDN Ryu Denial of Service Vulnerability
CVE-2023-4241High· 7.5lol-html panics on certain HTML inputs
lol-html panics on certain HTML inputs
CVE-2023-3518High· 7.4Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
CVE-2023-33953High· 7.5Excessive Iteration in gRPC
Excessive Iteration in gRPC
CVE-2023-39523Medium· 6.8ScanCode.io command injection in docker image fetch process
ScanCode.io command injection in docker image fetch process
CVE-2023-39965Medium· 6.51Panel Arbitrary File Download vulnerability
1Panel Arbitrary File Download vulnerability
CVE-2023-39531Medium· 6.5Sentry vulnerable to incorrect credential validation on OAuth token requests
Sentry vulnerable to incorrect credential validation on OAuth token requests
Most-affected vendors
By CVEs published in the period.