Weekly digest
Week 50, 2023 (11–17 Dec)
18 new CVEs this week, in line with the recent average. Severity skewed high: 4 critical and 5 high, 50% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. redhat was the most-affected vendor with 3.
New this week, ranked by depth score
The 12 that matter most of the 18 published.
CVE-2023-6572Critical· 9.6PoCGradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2023-50918Critical· 9.8app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.
app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.
CVE-2023-50423Critical· 9.1Improper Privilege Management in sap-xssec
Improper Privilege Management in sap-xssec
CVE-2023-50422Critical· 9.1Improper Privilege Management in github.com/sap/cloud-security-client-go
Improper Privilege Management in github.com/sap/cloud-security-client-go
CVE-2023-6563High· 7.7An unconstrained memory consumption vulnerability was discovered in Keycloak
An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates …
CVE-2023-6377High· 7.8A flaw was found in xorg-server
A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code exe…
CVE-2023-6478High· 7.6A flaw was found in xorg-server
A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.
CVE-2023-6710Medium· 5.4PoCA flaw was found in the mod_proxy_cluster in the Apache server
A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script …
CVE-2023-46247High· 7.5incorrect storage layout for contracts containing large arrays
incorrect storage layout for contracts containing large arrays
CVE-2023-5379High· 7.5A flaw was found in Undertow
A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without re…
CVE-2023-5764Medium· 6.6Ansible template injection vulnerability
Ansible template injection vulnerability
CVE-2023-49795Medium· 6.5Server-Side Request Forgery in mindsdb
Server-Side Request Forgery in mindsdb
Most-affected vendors
By CVEs published in the period.