Weekly digest
Week 51, 2023 (18–24 Dec)
14 new CVEs this week, in line with the recent average. Severity skewed high: 1 critical and 7 high, 57% of the total. 5 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. apache-superset was the most-affected vendor with 3.
New this week, ranked by depth score
The 12 that matter most of the 14 published.
CVE-2023-51449High· 8.6PoCGradio makes the `/file` secure against file traversal and server-side request forgery attacks
Gradio makes the `/file` secure against file traversal and server-side request forgery attacks
CVE-2023-6546High· 7.00dayPoCA race condition was found in the GSM 0710 tty multiplexor in the Linux kernel
A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a u…
CVE-2023-48795Medium· 5.9PoCPrefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
CVE-2023-6931High· 7.8PoCA heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increme…
A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increme…
CVE-2023-6977High· 7.5PoCMLflow Local File Disclosure Vulnerability
MLflow Local File Disclosure Vulnerability
CVE-2023-27172Critical· 9.1Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens
Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.
CVE-2023-6976High· 8.8MLflow Path Traversal Vulnerability
MLflow Path Traversal Vulnerability
CVE-2023-6940High· 8.8mlflow Command Injection vulnerability
mlflow Command Injection vulnerability
CVE-2023-49734High· 7.7Apache Superset incorrect write permissions vulnerability
Apache Superset incorrect write permissions vulnerability
CVE-2023-49736Medium· 6.5Apache Superset SQL injection vulnerability
Apache Superset SQL injection vulnerability
CVE-2023-46104Medium· 6.5Apache Superset uncontrolled resource consumption
Apache Superset uncontrolled resource consumption
CVE-2023-51384Medium· 5.5In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied
In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first k…
Most-affected vendors
By CVEs published in the period.