NA - CVE-2023-43631 -
On boot, the Pillar eve container checks for...
On boot, the Pillar eve container checks for the existence and content of “/config/authorized_keys”. If the file is present, and contains a supported public key, the container will go on to open...
NA - CVE-2023-43632 -
As noted in the “VTPM.md” file in the eve...
As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limited functionality of the TPM to the clients. VTPM allows clients to execute...
NA - CVE-2023-43633 -
On boot, the Pillar eve container checks for...
On boot, the Pillar eve container checks for the existence and content of “/config/GlobalConfig/global.json”. If the file exists, it overrides the existing configuration on the device on boot....
NA - CVE-2023-43634 -
When sealing/unsealing the “vault” key, a list...
When sealing/unsealing the “vault” key, a list of PCRs is used, which defines which PCRs are used. In a previous project, CYMOTIVE found that the configuration is not protected by the secure...
NA - CVE-2023-43637 -
Due to the implementation of "deriveVaultKey",...
Due to the implementation of "deriveVaultKey", prior to version 7.10, the generated vault key would always have the last 16 bytes predetermined to be "arfoobarfoobarfo". This issue happens...
NA - CVE-2023-40183 - DataEase is an open source data visualization...
DataEase is an open source data visualization and analysis tool. Prior to version 1.18.11, DataEase has a vulnerability that allows an attacker to to obtain user cookies. The program only uses the...
NA - CVE-2023-41048 - plone.namedfile allows users to handle `File`...
plone.namedfile allows users to handle `File` and `Image` fields targeting, but not depending on, Plone Dexterity content. Prior to versions 5.6.1, 6.0.3, 6.1.3, and 6.2.1, there is a stored cross...
NA - CVE-2023-42457 - plone.rest allows users to use HTTP verbs such...
plone.rest allows users to use HTTP verbs such as GET, POST, PUT, DELETE, etc. in Plone. Starting in the 2.x branch and prior to versions 2.0.1 and 3.0.1, when the `++api++` traverser is...
NA - CVE-2023-42456 - Sudo-rs, a memory safe implementation of sudo...
Sudo-rs, a memory safe implementation of sudo and su, allows users to not have to enter authentication at every sudo attempt, but instead only requiring authentication every once in a while in...
NA - CVE-2023-34577 - SQL injection vulnerability in Prestashop...
SQL injection vulnerability in Prestashop opartplannedpopup 1.4.11 and earlier allows remote attackers to run arbitrary SQL commands via OpartPlannedPopupModuleFrontController::prepareHook() method.