CVE Vulnerabilities

CVE-2023-35853

Published: Jun 19, 2023 | Modified: Dec 11, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section.

Affected Software

NameVendorStart VersionEnd Version
SuricataOisf*6.0.13 (excluding)
SuricataUbuntubionic*
SuricataUbuntukinetic*
SuricataUbuntulunar*
SuricataUbuntumantic*
SuricataUbuntuoracular*
SuricataUbuntuplucky*
SuricataUbuntutrusty*
SuricataUbuntuxenial*

References