Weekly digest
Week 4, 2024 (22–28 Jan)
14 new CVEs this week, in line with the recent average. Severity skewed high: 7 high, 50% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries.
New this week, ranked by depth score
The 12 that matter most of the 14 published.
CVE-2023-52251High· 8.8PoCAn issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages
An issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages. No fixed release is available; the project has had no com…
CVE-2023-47115High· 7.1PoCCross-site Scripting Vulnerability on Avatar Upload
Cross-site Scripting Vulnerability on Avatar Upload
CVE-2023-40547High· 8.3A remote code execution vulnerability was found in Shim
A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a complet…
CVE-2023-52355High· 7.5An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smal…
CVE-2024-23342High· 7.4Minerva timing attack on P-256 in python-ecdsa
Minerva timing attack on P-256 in python-ecdsa
CVE-2023-6291High· 7.1A flaw was found in the redirect_uri validation logic in Keycloak
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to …
CVE-2024-23345High· 7.1XSS potential in rendered Markdown fields (comments, description, notes, etc.)
XSS potential in rendered Markdown fields (comments, description, notes, etc.)
CVE-2024-0775Medium· 6.7A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel
A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a local user to cause an information leak problem while freeing the old quota file names before a potential failure, l…
CVE-2023-51702Medium· 6.5Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in met…
Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in met…
CVE-2024-23341Medium· 6.1html injection vulnerability in the `tuitse_html` function.
html injection vulnerability in the `tuitse_html` function.
CVE-2024-0727Medium· 5.5Null pointer dereference in PKCS12 parsing
Null pointer dereference in PKCS12 parsing
CVE-2024-0960Medium· 5.0ai-flow Deserialization of Untrusted Data vulnerability
ai-flow Deserialization of Untrusted Data vulnerability
Most-affected vendors
By CVEs published in the period.