Weekly digest
Week 46, 2023 (13–19 Nov)
A heavy week: 29 new CVEs, well above the recent average of about 13. Severity skewed high: 9 critical and 9 high, 62% of the total. 5 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. vim was the most-affected vendor with 7.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 29 published.
CVE-2023-6019Critical· 9.8PoCRay OS Command Injection vulnerability
Ray OS Command Injection vulnerability
CVE-2023-6021Critical· 9.3PoCRay Path Traversal vulnerability
Ray Path Traversal vulnerability
CVE-2023-6020Critical· 9.3PoCRay Missing Authorization vulnerability
Ray Missing Authorization vulnerability
CVE-2023-47630High· 7.1⚠ Exploited0dayAttacker can cause Kyverno user to unintentionally consume insecure image
Attacker can cause Kyverno user to unintentionally consume insecure image
CVE-2023-48659Critical· 9.8An issue was discovered in MISP before 2.4.176
An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.
CVE-2023-48658Critical· 9.8An issue was discovered in MISP before 2.4.176
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and space.
CVE-2023-48657Critical· 9.8An issue was discovered in MISP before 2.4.176
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.
CVE-2023-48656Critical· 9.8An issue was discovered in MISP before 2.4.176
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.
CVE-2023-48655Critical· 9.8An issue was discovered in MISP before 2.4.176
An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.
CVE-2023-47117High· 7.5PoCLabel Studio Object Relational Mapper Leak Vulnerability in Filtering Task
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
CVE-2023-43902Critical· 9.8Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.
Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.
CVE-2023-6022High· 8.8Cross-Site Request Forgery vulnerability in Prefect
Cross-Site Request Forgery vulnerability in Prefect
Most-affected vendors
By CVEs published in the period.