Weekly digest
Week 3, 2024 (15–21 Jan)
A heavy week: 28 new CVEs, well above the recent average of about 16. Severity skewed high: 5 critical and 13 high, 64% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. linux was the most-affected vendor with 3.
New this week, ranked by depth score
The 12 that matter most of the 28 published.
CVE-2023-27168Critical· 9.8PoCAn arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.
An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.
CVE-2024-22416Critical· 9.6PoCCross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation
Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation
CVE-2024-23679Critical· 9.8Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue
Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes.
CVE-2024-0521Critical· 9.3Code Injection in paddlepaddle
Code Injection in paddlepaddle
CVE-2024-23687Critical· 9.1Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations including single-sign-on, and manipulate f…
Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations including single-sign-on, and manipulate f…
CVE-2024-23689High· 8.8Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificat…
Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificat…
CVE-2024-22424High· 8.3github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
CVE-2024-23683High· 8.2Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException
Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker can abuse this issue to execute arbitrary Java when a victim execu…
CVE-2024-23682High· 8.2Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a package that Ares trusts
Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a package that Ares trusts. An attacker can abuse this issue to execute arbitrary Java when a victim executes the…
CVE-2024-23681High· 8.2Artemis Java Test Sandbox versions before 1.11.2 are vulnerable to a sandbox escape when an attacker loads untrusted libraries using System.load or System.loadLibrary
Artemis Java Test Sandbox versions before 1.11.2 are vulnerable to a sandbox escape when an attacker loads untrusted libraries using System.load or System.loadLibrary. An attacker can abuse this issue to execute arbitrary Java when a vic…
CVE-2023-50447High· 8.1Arbitrary Code Execution in Pillow
Arbitrary Code Execution in Pillow
CVE-2024-22421High· 7.6JupyterLab vulnerable to potential authentication and CSRF tokens leak
JupyterLab vulnerable to potential authentication and CSRF tokens leak
Most-affected vendors
By CVEs published in the period.