Weekly digest
Week 43, 2023 (23–29 Oct)
A busier-than-usual week with 21 new CVEs (recent average about 15). Of those, 1 critical and 9 high. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. ethyca-fides was the most-affected vendor with 3.
New this week, ranked by depth score
The 12 that matter most of the 21 published.
CVE-2023-5043High· 7.6PoCIngress nginx annotation injection causes arbitrary command execution
Ingress nginx annotation injection causes arbitrary command execution
CVE-2023-27170High· 7.5PoCXpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.
Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.
CVE-2023-46233Critical· 9.1crypto-js is a JavaScript library of crypto standards
crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry standard. This is because …
CVE-2022-4886High· 8.8Ingress-nginx path sanitization can be bypassed
Ingress-nginx path sanitization can be bypassed
CVE-2023-46124High· 8.2Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload
Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload
CVE-2023-46136Medium· 5.7PoCWerkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
CVE-2023-5367High· 7.8A out-of-bounds write flaw was found in the xorg-x11-server
A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRCha…
CVE-2023-46128High· 7.7Nautobot vulnerable to exposure of hashed user passwords via REST API
Nautobot vulnerable to exposure of hashed user passwords via REST API
CVE-2023-46215High· 7.5Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
CVE-2023-4692High· 7.5An out-of-bounds write flaw was found in grub2's NTFS filesystem driver
An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack…
CVE-2023-5574High· 7.0A use-after-free flaw was found in xorg-x11-server-Xvfb
A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped f…
CVE-2023-46125Medium· 6.5Fides Information Disclosure Vulnerability in Config API Endpoint
Fides Information Disclosure Vulnerability in Config API Endpoint
Most-affected vendors
By CVEs published in the period.