VulnSea

Weekly digest

Week 49, 2023 (4–10 Dec)

16 new CVEs this week, in line with the recent average. Of those, 4 high. One arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. traefik was the most-affected vendor with 3.

16
New CVEs
0
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 16 published.

CVE-2023-43472High· 7.5PoC
2y ago

Information exposure in MLflow

Information exposure in MLflow

▾ Midnightmlflow · mlflowEPSS 37%via OSV
CVE-2023-47633High· 7.5
2y ago

Traefik docker container using 100% CPU

Traefik docker container using 100% CPU

▾ Twilighttraefik · github.com/traefik/traefik/v2EPSS 1.3%via OSV
CVE-2023-6610High· 7.1
2y ago

An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel

An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information.

▾ Twilightlinux · linux_kernelEPSS 0.43%via NVD
CVE-2023-6458High· 7.1
2y ago

Mattermost Injection vulnerability

Mattermost Injection vulnerability

▾ Twilightmattermost · github.com/mattermost/mattermost-server/v6EPSS 0.64%via OSV
CVE-2023-47106Medium· 6.5
2y ago

Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass

Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass

▾ Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.63%via OSV
CVE-2023-6507Medium· 6.1
2y ago

An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms

An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases. When using the `extra_groups=` parameter with an empty list as a value (ie `ex…

▾ Sunlitpython · pythonEPSS 1.3%via NVD
CVE-2023-26154Medium· 5.9
2y ago

pubnub Insufficient Entropy vulnerability

pubnub Insufficient Entropy vulnerability

▾ Sunlitpubnub · pubnubEPSS 0.96%via OSV
CVE-2023-47124Medium· 5.9
2y ago

Traefik vulnerable to potential DDoS via ACME HTTPChallenge

Traefik vulnerable to potential DDoS via ACME HTTPChallenge

▾ Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.79%via OSV
CVE-2023-6459Medium· 5.3
2y ago

Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability

▾ Sunlitmattermost · github.com/mattermost/mattermost-server/v6EPSS 0.53%via OSV
CVE-2023-6393Medium· 5.3
2y ago

A flaw was found in the Quarkus Cache Runtime

A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the cached Uni reuses the initial "completion" context, the processing switches to the cached Uni instead of the request …

▾ Sunlitredhat · build_of_quarkusEPSS 0.63%via NVD
CVE-2023-6180Medium· 5.3
2y ago

tokio-boring vulnerable to resource exhaustion via memory leak

tokio-boring vulnerable to resource exhaustion via memory leak

▾ Sunlittokio-boring · tokio-boringEPSS 0.62%via OSV
CVE-2023-49290Medium· 5.3
2y ago

lestrrat-go/jwx's malicious parameters in JWE can cause a DOS

lestrrat-go/jwx's malicious parameters in JWE can cause a DOS

▾ Sunlitlestrrat-go · github.com/lestrrat-go/jwxEPSS 0.73%via OSV

Most-affected vendors

By CVEs published in the period.