Weekly digest
Week 33, 2023 (14–20 Aug)
A quiet week: only 4 new CVEs against a recent average of about 11. Severity skewed high: 3 high, 75% of the total. No new KEV entries.
4
New CVEs
0
Critical
0
KEV additions
0
Records changed
New this week, ranked by depth score
The 4 that matter most of the 4 published.
CVE-2023-40034High· 8.1Woodpecker does not validate webhook before changing any data
Woodpecker does not validate webhook before changing any data
▾ Twilightwoodpecker-ci · github.com/woodpecker-ci/woodpeckerEPSS 0.88%via OSV
CVE-2023-40283High· 7.8An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10
An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled.
▾ TwilightEPSS 0.55%via CVEORG
CVE-2023-40272High· 7.5Apache Airflow Spark Provider Improper Input Validation vulnerability
Apache Airflow Spark Provider Improper Input Validation vulnerability
▾ Twilightapache-airflow-providers-apache-spark · apache-airflow-providers-apache-sparkEPSS 2.1%via OSV
CVE-2023-40024Medium· 6.1Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint
Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint
▾ Sunlitscancodeio · scancodeioEPSS 0.51%via OSV
Most-affected vendors
By CVEs published in the period.