← Zuruck zu CVEs
CVE-2023-35853
CRITICAL9.8
Beschreibung
In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht6/19/2023
Zuletzt geandert12/11/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
oisf:suricata
Schwachen (CWE)
CWE-94
Referenzen
https://www.stamus-networks.com/stamus-labs(cve@mitre.org)
https://github.com/OISF/suricata/commit/b95bbcc66db526ffcc880eb439dbe8abc87a81da(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/OISF/suricata/compare/suricata-6.0.12...suricata-6.0.13(af854a3a-2127-422b-91ae-364da2661108)
https://www.stamus-networks.com/stamus-labs(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.