Weekly digest
Week 48, 2023 (27 Nov – 3 Dec)
A busier-than-usual week with 18 new CVEs (recent average about 14). Of those, 1 critical and 3 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. apache-superset was the most-affected vendor with 6.
New this week, ranked by depth score
The 12 that matter most of the 18 published.
CVE-2023-48022Critical· 9.8PoCRay has arbitrary code execution via jobs submission API
Ray has arbitrary code execution via jobs submission API
CVE-2023-49097High· 8.1ZITADEL Account Takeover via Malicious Host Header Injection
ZITADEL Account Takeover via Malicious Host Header Injection
CVE-2023-49081High· 7.2aiohttp is an asynchronous HTTP client/server framework for asyncio and Python
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create a new HTTP request if the attacker co…
CVE-2023-40610High· 7.3Apache Superset - Elevation of Privilege
Apache Superset - Elevation of Privilege
CVE-2023-42504Medium· 6.5Apache Superset Allocation of Resources Without Limits or Throttling vulnerability
Apache Superset Allocation of Resources Without Limits or Throttling vulnerability
CVE-2023-49926Medium· 6.1app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.
app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.
CVE-2023-49277Medium· 6.1Reflected XSS Vulnerability in dpaste
Reflected XSS Vulnerability in dpaste
CVE-2023-49083Medium· 5.9cryptography vulnerable to NULL-dereference when loading PKCS7 certificates
cryptography vulnerable to NULL-dereference when loading PKCS7 certificates
CVE-2023-42502Medium· 5.4Apache Superset Open Redirect vulnerability
Apache Superset Open Redirect vulnerability
CVE-2023-49082Medium· 5.3aiohttp is an asynchronous HTTP client/server framework for asyncio and Python
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker…
CVE-2023-34054Medium· 5.3In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an …
In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an …
CVE-2023-48369Medium· 5.3Mattermost Uncontrolled Resource Consumption vulnerability
Mattermost Uncontrolled Resource Consumption vulnerability
Most-affected vendors
By CVEs published in the period.