CVE Vulnerabilities

CVE-2023-35853

Published: Jun 19, 2023 | Modified: Dec 11, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section.

Affected Software

Name Vendor Start Version End Version
Suricata Oisf * 6.0.13 (excluding)
Suricata Ubuntu bionic *
Suricata Ubuntu kinetic *
Suricata Ubuntu lunar *
Suricata Ubuntu mantic *
Suricata Ubuntu trusty *
Suricata Ubuntu xenial *

References