Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In July 2023
DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb into an HTTP response
CVSS Score
5.9
EPSS Score
0.002
Published
2023-07-19
The Data Exchange Add-on component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged user with import permissions and network access to the EBX server to execute arbitrary SQL statements on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.5.17 and below, versions 5.6.2 and below, version 6.1.0.
CVSS Score
8.8
EPSS Score
0.002
Published
2023-07-19
An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.
CVSS Score
8.6
EPSS Score
0.498
Published
2023-07-19
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled with llhttp v6.0.6. Vulnerable code is used by aiohttp for its HTTP request parser when available which is the default case when installing from a wheel. This vulnerability only affects users of aiohttp as an HTTP server (ie `aiohttp.Application`), you are not affected by this vulnerability if you are using aiohttp as an HTTP client library (ie `aiohttp.ClientSession`). Sending a crafted HTTP request will cause the server to misinterpret one of the HTTP header values leading to HTTP request smuggling. This issue has been addressed in version 3.8.5. Users are advised to upgrade. Users unable to upgrade can reinstall aiohttp using `AIOHTTP_NO_EXTENSIONS=1` as an environment variable to disable the llhttp HTTP request parser implementation. The pure Python implementation isn't vulnerable.
CVSS Score
5.3
EPSS Score
0.058
Published
2023-07-19
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Feathers socket handler did not catch invalid string conversion errors like `const message = ${{ toString: '' }}` which would cause the NodeJS process to crash when sending an unexpected Socket.io message like `socket.emit('find', { toString: '' })`. A fix has been released in versions 5.0.8 and 4.5.18. Users are advised to upgrade. There is no known workaround for this vulnerability.
CVSS Score
7.5
EPSS Score
0.002
Published
2023-07-19
Reflected Cross-Site Scripting (XSS)
CVSS Score
8.3
EPSS Score
0.009
Published
2023-07-19
Privilege Escalation to root administrator (nsroot)
CVSS Score
8.0
EPSS Score
0.004
Published
2023-07-19
A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.
CVSS Score
2.3
EPSS Score
0.0
Published
2023-07-19
An arbitrary file upload vulnerability in tduck-platform v4.0 allows attackers to execute arbitrary code via a crafted HTML file.
CVSS Score
6.1
EPSS Score
0.001
Published
2023-07-19
CVE-2023-3519
Known exploited
Unauthenticated remote code execution
CVSS Score
9.8
EPSS Score
0.9
Published
2023-07-19


Contact Us

Shodan ® - All rights reserved