Weekly digest
Week 40, 2023 (2–8 Oct)
10 new CVEs this week, in line with the recent average. Severity skewed high: 2 critical and 3 high, 50% of the total. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries.
New this week, ranked by depth score
The 10 that matter most of the 10 published.
CVE-2023-43654Critical· 9.8PoCTorchServe Server-Side Request Forgery vulnerability
TorchServe Server-Side Request Forgery vulnerability
CVE-2023-43261High· 7.5PoCAn information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
CVE-2023-32188CriticalJWT token compromise can allow malicious actions including Remote Code Execution (RCE)
JWT token compromise can allow malicious actions including Remote Code Execution (RCE)
CVE-2023-4570High· 8.8NI MeasurementLink Python Services Improper Access Restriction vulnerability
NI MeasurementLink Python Services Improper Access Restriction vulnerability
CVE-2023-43804Medium· 5.9PoC`Cookie` HTTP header isn't stripped on cross-origin redirects
`Cookie` HTTP header isn't stripped on cross-origin redirects
CVE-2023-43810High· 7.5opentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metrics
opentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metrics
CVE-2023-4237Medium· 6.5Ansible may expose private key
Ansible may expose private key
CVE-2023-44378Medium· 5.5gnark unsoundness in variable comparison / non-unique binary decomposition
gnark unsoundness in variable comparison / non-unique binary decomposition
CVE-2023-3576Medium· 5.5A memory leak flaw was found in Libtiff's tiffcrop utility
A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image file, allowing an attacker to pass a crafted TIFF image file to tiffcrop utility, which causes this memory leak issue, r…
CVE-2023-44389Low· 3.1Zope management interface vulnerable to stored cross site scripting via the title property
Zope management interface vulnerable to stored cross site scripting via the title property
Most-affected vendors
By CVEs published in the period.