Mastodon fixes critical “TootRoot” vulnerability allowing node hijacking

Mastodon fixes critical “TootRoot” vulnerability allowing node hijacking

The maintainers of the open source software that powers the Mastodon social network published a security update on Thursday that patches a critical vulnerability making it possible for hackers to backdoor the servers that push content to individual users.

Mastodon is based on a federated model. The federation comprises thousands of separate servers known as “instances.” Individual users create an account with one of the instances, which in turn exchange content to and from users of other instances. To date, Mastodon has more than 24,000 instances and 14.5 million users, according to the-federation.info, a site that tracks statistics related to Mastodon.

A critical bug tracked as CVE-2023-36460 was one of two vulnerabilities rated as critical that were fixed on Thursday. In all, Mastodon on Thursday patched five vulnerabilities.

So far, Mastodon gGmbH, the nonprofit that maintains the software instances uses to operate the social network, has released few details about CVE-2023-36460 other than to describe it as an “arbitrary file creation through media attachments” flaw.

“Using carefully crafted media files, attackers can cause Mastodon’s media processing code to create arbitrary files at any location,” Mastodon said. “This allows attackers to create and overwrite any file Mastodon has access to, allowing Denial of Service and arbitrary Remote Code Execution.”

In a Mastodon post, independent security researcher Kevin Beaumont went a step further, writing that exploiting the vulnerability allowed someone “to send a toot which makes a webshell on instances that process said toot.” He coined the name #TootRoot because user posts, known as toots, allowed hackers to potentially gain root access to instances.

An attacker with control over thousands of instances could inflict all kinds of harm on individual users and possibly the larger Internet. For example, hijacked instances could send alerts to users instructing them to download and install malicious apps or bring the entire infrastructure to a halt. There are no indications that the bug has ever been exploited.

Thursday’s patch is the product of recent penetration testing work that the Mozilla Foundation funded, Mastodon cofounder and CTO Renaud Chaput told Ars. He said a firm called Cure53 performed the pentesting and that the code fixes were developed by the several-person team inside the Mastodon nonprofit. Mozilla has announced plans to create its own Mastodon instance. Rinaud said that Mastodon sent pre-announcements to large servers in recent weeks, informing them of the fix so they would be ready to patch quickly.

In all, Mastodon’s Thursday patch batch fixed five vulnerabilities. One of the bugs, tracked as CVE-2023-36459, also carried a critical severity rating. Mastodon’s bare-bones writeup described the flaw as an “XSS through oEmbed preview cards.”

It continued: “Using carefully crafted oEmbed data, an attacker can bypass the HTML sanitization performed by Mastodon and include arbitrary HTML in oEmbed preview cards. This introduces a vector for Cross-site-scripting (XSS) payloads that can be rendered in the user’s browser when a preview card for a malicious link is clicked through.”

XSS exploits allow hackers to inject malicious code into websites, which in turn cause it to run in the browsers of people visiting the site. oEmbed is an open format for allowing an embedded representation of a URL on third-party sites. No other details about the vulnerability were immediately available.

The three other vulnerabilities carried high and medium severity ratings. They included a “Blind LDAP injection in login [that[ allows the attacker to leak arbitrary attributes from LDAP database,” “Denial of Service through slow HTTP responses,” and “Verified profile links [that] can be formatted in a misleading way.”

The patches come as social media behemoth Meta rolled out a new service intended to pick up Twitter users who are leaving the platform. There’s no action individual Mastodon users need to take other than to ensure that the instance they’re subscribed to has installed the updates.

Updated to fix description of Cure53.

https://arstechnica.com/?p=1951981




StackRot Linux Kernel Vulnerability Shows Exploitability of UAFBR Bugs

A researcher has disclosed a Linux kernel vulnerability that he claims is the first to demonstrate that a type of bug called use-after-free-by-RCU (UAFBR) is exploitable.

The vulnerability, named StackRot and officially tracked as CVE-2023-3269, was reported to Linux kernel developers on June 15 by researcher Ruihan Li. 

The flaw has been present in the kernel since version 6.1 and patches were made available on July 1 with the release of versions 6.1.37, 6.3.11 and 6.4.1.

The researcher made public some information on StackRot this week, but a complete exploit and a detailed write-up are expected to be released at the end of July. 

According to the researcher, the issue impacts the memory management subsystem and it can allow an unprivileged local user to compromise the kernel and escalate privileges. 

While nearly all kernel configurations are affected and minimal capabilities are required to trigger the bug, the researcher pointed out that exploiting the vulnerability is not easy.

“The maple tree, responsible for managing virtual memory areas, can undergo node replacement without properly acquiring the MM write lock, leading to use-after-free issues,” he explained. 

Advertisement. Scroll to continue reading.

“However, it should be noted that maple nodes are freed using RCU callbacks, delaying the actual memory deallocation until after the RCU grace period. Consequently, exploiting this vulnerability is considered challenging,” he added. 

The researcher believes there are no other publicly available exploits targeting these UAFBR bugs and this is the first time it has been proven that they are exploitable. 

The exploit has been executed in the kCTF Kubernetes-based environment for CTF competitions provided by Google. 

Related: CISA Says ‘PwnKit’ Linux Vulnerability Exploited in Attacks

Related: CISA Tells Organizations to Patch Linux Kernel Vulnerability Exploited by Malware

Related: Polkit Vulnerability Provides Root Privileges on Linux Systems

https://www.securityweek.com/stackrot-linux-kernel-vulnerability-shows-exploitability-of-uafbr-bugs/




Vulnerability in Cisco Enterprise Switches Allows Attackers to Modify Encrypted Traffic

Cisco this week informed customers about a high-severity vulnerability in its Nexus 9000 series switches that could allow unauthenticated attackers to intercept and modify traffic.

Tracked as CVE-2023-20185, the issue impacts the ACI multi-site CloudSec encryption feature of the Nexus 9000 switches that are configured in application centric infrastructure (ACI) mode – typically used in data centers for controlling physical and virtual networks.

An issue with the implementation of the ciphers used by the CloudSec encryption feature allows a remote, unauthenticated attacker to intercept encrypted traffic between sites and break the encryption using cryptanalytic techniques. The attacker could then read or modify the traffic.

“This vulnerability affects Cisco Nexus 9000 Series Fabric Switches in ACI mode that are running releases 14.0 and later if they are part of a multi-site topology and have the CloudSec encryption feature enabled,” Cisco explains in an advisory.

The issue impacts Nexus 9332C and Nexus 9364C fixed spine switches, and Nexus 9500 spine switches equipped with a Nexus N9K-X9736C-FX line card.

Cisco has not released patches to address the vulnerability and recommends that customers using vulnerable switches disable the ACI multi-site CloudSec encryption feature.

This week, the tech giant released software updates to address four medium-severity issues in Webex Meetings, Duo Authentication Proxy, and BroadWorks.

Advertisement. Scroll to continue reading.

Successful exploitation of these vulnerabilities could lead to cross-site scripting (XSS) or cross-site request forgery (CSRF) attacks, information leaks, and privilege escalation.

Cisco says it is not aware of any malicious attacks or public proof-of-concept (PoC) code targeting these flaws. Additional information on the vulnerabilities can be found on Cisco’s security advisories page.

Related: PoC Exploit Published for Cisco AnyConnect Secure Vulnerability

Related: Cisco Patches Critical Vulnerability in Enterprise Collaboration Solutions

Related: Cisco Says PoC Exploits Available for Newly Patched Enterprise Switch Vulnerabilities

https://www.securityweek.com/vulnerability-in-cisco-enterprise-switches-allows-attackers-to-modify-encrypted-traffic/




Actively exploited vulnerability threatens hundreds of solar power stations

Actively exploited vulnerability threatens hundreds of solar power stations
Getty Images

Hundreds of Internet-exposed devices inside solar farms remain unpatched against a critical and actively exploited vulnerability that makes it easy for remote attackers to disrupt operations or gain a foothold inside the facilities.

The devices, sold by Osaka, Japan-based Contec under the brand name SolarView, help people inside solar facilities monitor the amount of power they generate, store, and distribute. Contec says that roughly 30,000 power stations have introduced the devices, which come in various packages based on the size of the operation and the type of equipment it uses.

Searches on Shodan indicate that more than 600 of them are reachable on the open Internet. As problematic as that configuration is, researchers from security firm VulnCheck said Wednesday, more than two-thirds of them have yet to install an update that patches CVE-2022-29303, the tracking designation for a vulnerability with a severity rating of 9.8 out of 10. The flaw stems from the failure to neutralize potentially malicious elements included in user-supplied input, leading to remote attacks that execute malicious commands.

Security firm Palo Alto Networks said last month the flaw was under active exploit by an operator of Mirai, an open source botnet consisting of routers and other so-called Internet of Things devices. The compromise of these devices could cause facilities that use them to lose visibility into their operations, which could result in serious consequences depending on where the vulnerable devices are used.

“The fact that a number of these systems are Internet facing and that the public exploits have been available long enough to get rolled into a Mirai-variant is not a good situation,” VulnCheck researcher Jacob Baines wrote. “As always, organizations should be mindful of which systems appear in their public IP space and track public exploits for systems that they rely on.”

Baines said that the same devices vulnerable to CVE-2022-29303 were also vulnerable to CVE-2023-23333, a newer command-injection vulnerability that also has a severity rating of 9.8. Although there are no known reports of it being actively exploited, exploit code has been publicly available since February.

Incorrect descriptions for both vulnerabilities are one factor involved in the patch failures, Baines said. Both vulnerabilities indicate that SolarView versions 8.00 and 8.10 are patched against CVE-2022-29303 and CVE-2023-293333. In fact, the researcher said, only 8.10 is patched against the threats.

Palo Alto Networks said the exploit activity for CVE-2022-29303 is part of a broad campaign that exploited 22 vulnerabilities in a range of IoT devices in an attempt to spread a Marai variant. The attacks started in March and attempted to use the exploits to install a shell interface that allows devices to be controlled remotely. Once exploited, a device downloads and executes the bot clients that are written for various Linux architectures.

There are indications that the vulnerability was possibly being targeted even earlier. Exploit code has been available since May 2022. This video from the same month shows an attacker searching Shodan for a vulnerable SolarView system and then using the exploit against it.

While there are no indications that attackers are actively exploiting CVE-2023-23333, there are multiple exploits on GitHub.

There’s no guidance on the Contec website about either vulnerability and company representatives didn’t immediately respond to emailed questions. Any organization using one of the affected devices should update as soon as possible. Organizations should also check to see if their devices are exposed to the Internet and, if so, change their configurations to ensure the devices are reachable only on internal networks.

https://arstechnica.com/?p=1951780




Exploited Solar Power Product Vulnerability Could Expose Energy Organizations to Attacks

Hundreds of energy organizations could be exposed to attacks due to an actively exploited vulnerability affecting a solar power monitoring product made by Contec, vulnerability intelligence company VulnCheck warned on Wednesday.

Contec specializes in custom embedded computing, industrial automation, and IoT communication technology. The company’s SolarView solar power monitoring and visualization product is used at more than 30,000 power stations, according to its website.

Palo Alto Networks reported on June 22 that a Mirai variant has been exploiting a vulnerability in SolarView to hack devices and ensnare them into a botnet. The flaw, CVE-2022-29303, is one of the nearly two dozen targeted by the botnet. 

CVE-2022-29303 is described as a code injection issue affecting SolarView version 6.0. The vulnerability can be exploited remotely by unauthenticated attackers. 

VulnCheck’s analysis indicates that the security hole was only patched with the release of version 8.0 and versions dating back to at least 4.0 are impacted. 

A Shodan search shows more than 600 internet-exposed SolarView systems, including over 400 running vulnerable versions. 

“When considered in isolation, exploitation of this system is not significant. The SolarView series are all monitoring systems, so loss of view (T0829) is likely the worst-case scenario. However, the impact of exploitation could be high, depending on the network the SolarView hardware is integrated into,” VulnCheck explained.

Advertisement. Scroll to continue reading.

“For instance, if the hardware is part of a solar power generation site, then the attacker may affect loss of productivity and revenue (T0828) by using the hardware as a network pivot to attack other ICS resources,” it added.

The fact that CVE-2022-29303 has been used in the wild is not surprising considering that an exploit and exploitation instructions have been public since May 2022. 

In addition, VulnCheck warned that there are other, including more recent, SolarView vulnerabilities that could be exploited by malicious actors, including CVE-2023-23333 and CVE-2022-44354.

Related: Omron PLC Vulnerability Exploited by Sophisticated ICS Malware

Related: Details Disclosed for OPC UA Vulnerabilities Exploited at ICS Hacking Competition

Related: CISA: Vulnerability in ​​Delta Electronics ICS Software Exploited in Attacks

Related: CosmicEnergy ICS Malware Poses No Immediate Threat, but Should Not Be Ignored

https://www.securityweek.com/exploited-solar-power-product-vulnerability-could-expose-energy-organizations-to-attacks/




Firefox 115 Patches High-Severity Use-After-Free Vulnerabilities

Mozilla on Tuesday announced the release of Firefox 115 to the stable channel with patches for a dozen vulnerabilities, including two high-severity use-after-free bugs.

Tracked as CVE-2023-37201, the first of the high-severity issues is described as a use-after-free flaw in WebRTC certificate generation.

An open source project, WebRTC enables real-time communication in web browsers and mobile applications, via application programming interfaces (APIs).

“An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS,” Mozilla explains in an advisory.

The second high-severity vulnerability, CVE-2023-37202, is described as a potential use-after-free issue from compartment mismatch in the open source JavaScript and WebAssembly engine SpiderMonkey.

“Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free,” Mozilla says.

The browser maker says the latest Firefox update also addresses high-severity memory safety bugs that might have led to the execution of arbitrary code. The flaws are collectively tracked as CVE-2023-37211 and CVE-2023-37212.

Advertisement. Scroll to continue reading.

Firefox 115 also includes patches for eight medium-severity vulnerabilities leading to malicious sites placing trackers without permissions, arbitrary code execution, spoofing attacks, URL spoofing, download of files containing malicious code, use-after-free condition, and to tricking users into submitting sensitive data to malicious sites.

This week, Mozilla also announced that Firefox ESR 102.13 and Thunderbird 102.13 were released with patches for five vulnerabilities, including the high-severity use-after-free and memory safety bugs that were addressed in Firefox 115.

Additional information on the resolved vulnerabilities can be found on Mozilla’s security advisories page.

Related: Mozilla Patches High-Severity Vulnerabilities With Release of Firefox 111

Related: Firefox Updates Patch 10 High-Severity Vulnerabilities

Related: Firefox 107 Patches High-Impact Vulnerabilities

https://www.securityweek.com/firefox-115-patches-high-severity-use-after-free-vulnerabilities/




In Other News: Hospital Infected via USB Drive, EU Cybersecurity Rules, Free Security Tools

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under the radar.

We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape.

Each week, we will curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and industry reports.

Here are this week’s stories: 

USB drive infects hospital’s systems

Check Point provides an in-depth analysis of malware attributed to China-based espionage group Camaro Dragon that infected an European healthcare institution after an employee participated in a conference in Asia. The malware self-propagates through USB drives and landed on the healthcare organization’s systems after the employee’s drive was accidentally infected during the conference.

Political agreement reached on EU cybersecurity regulation

Advertisement. Scroll to continue reading.

A political agreement has been reached between the European Parliament and the Council of the EU regarding proposed cybersecurity rules whose goal is to boost security in EU institutions, bodies, offices and agencies. 

City of Dallas approved $4 million spend to bolster cyber defenses

After being hit by a ransomware attack in May, Dallas City Council this week approved a nearly $4 million contract to help improve cybersecurity and response.

UK, France issue cybersecurity warnings to law firms

Cybersecurity agencies in the UK and France have recently issued warnings to law firms, providing information on the threats they face and the steps they should take to become more resilient. 

NCSC updates risk management toolbox

The UK National Cyber Security Centre has updated its risk management guidance with three entirely new sections, including a cybersecurity risk management framework, a basic risk assessment and management method, and a risk management toolbox that includes five techniques to deal with risk management.

SolarWinds executives targeted by SEC over supply chain hack

Current and former SolarWinds executives have received a Wells notice from the SEC over the 2020 supply chain hack. The Wells notice indicates that the agency plans on bringing legal action against the executives. 

Jscrambler’s free PCI DSS JavaScript Compliance Tool

Jscrambler has released a tool that helps organizations meet requirements outlined by version 4.0 of the Payment Card Industry Data Security Standards (PCI DSS v4.0), which become mandatory in April 2025. The new PCI DSS JavaScript Compliance Tool is free for unlimited use, but a paid version is also available, with additional capabilities. 

Open source tools released by SEC Consult and Trustwave

SEC Consult has released DNS Analyzer, an open source Burp Suite extension for discovering DNS vulnerabilities in web applications. 

Trustwave has released Snappy, an open source tool for detecting rogue and fake 802.11 wireless access points by fingerprinting Beacon Management Frames.

Google Cloud launches GKE Security Posture dashboard 

Google Cloud announced the general availability of its Google Kubernetes Engine (GKE) Security Posture dashboard. The dashboard is designed to help streamline the security management of GKE clusters, providing features such as misconfiguration detection and vulnerability scanning. 

NanoLock, Otorio and TXOne announce new OT security solutions

NanoLock has announced the general availability of its OT Defender product for North American customers. The industrial cybersecurity product is designed to protect the integrity of manufacturing firms and OT assets from unauthorized access and changes.

TXOne Networks announced Stellar, a solution that leverages Cyber-Physical System Detection and Response (CPSDR) to prevent unexpected system changes from impacting operational reliability and availability.

Otorio announced the availability of its Attack Graph Analysis technology, which enables organizations to proactively manage vulnerabilities in their OT infrastructure. 

Grafana patches critical vulnerability 

Open source analytics and monitoring platform Grafana has released patches for a critical vulnerability leading to account takeover and access to sensitive information. Tracked as CVE-2023-3128, the vulnerability leads to authentication bypass when a multi-tenant Azure AD OAuth application is in use. 

Juniper releases out-of-band patches

Juniper Networks has released out-of-band JunosOS updates to patch an internally discovered high-severity vulnerability that can allow an unauthenticated, network-based attacker to cause a DoS condition.  

Mockingjay process injection technique

Security Joes have revealed a new process injection technique that can be used to evade EDR and XDR detection. Called Mockingjay, the technique abuses Windows libraries that have default read-write-execute (RWX) protections to inject code into processes and avoid using Windows APIs that security solutions typically monitor.

Related: In Other News: Microsoft Win32 App Isolation, Tsunami Hits Linux Servers, ChatGPT Credentials Exposed on Dark Web

Related: In Other News: AI Regulation, Layoffs, US Aerospace Attacks, Post-Quantum Encryption

https://www.securityweek.com/in-other-news-hospital-infected-via-usb-drive-eu-cybersecurity-rules-free-security-tools/




200,000 WordPress Sites Exposed to Attacks Exploiting Flaw in ‘Ultimate Member’ Plugin

More than 200,000 WordPress websites are exposed to ongoing attacks targeting a critical vulnerability in the Ultimate Member plugin.

Designed to make it easy for users to register and log in on sites, the plugin allows site owners to add user profiles, define roles, create custom form fields and member directories, and more.

Tracked as CVE-2023-3460 (CVSS score of 9.8), the recently identified security defect in Ultimate Member allows attackers to add a new user account to the administrators group.

Some of the plugin’s users have observed the creation of rogue accounts and reported them this week, but the attacks appear to have been ongoing at least since the beginning of June.

According to WordPress security firm WPScan, the issue is rooted in a conflict between the plugin’s blocklist logic and the way WordPress treats metadata keys.

Ultimate Member uses blocklists to store metadata keys that users should not manipulate and checks these lists whenever users attempt to register these keys when creating accounts.

Due to the difference in operation between the plugin and WordPress, attackers were able to trick the plugin into updating metadata keys, including one that stores user role and capabilities, WPScan explains. The company provides indicators of compromise (IoCs) associated with the observed attacks.

Advertisement. Scroll to continue reading.

This has allowed attackers to register user accounts with the administrator role, and at least two site owners have observed and reported the suspicious activity.

The plugin’s maintainers, who describe the issue as a privilege escalation bug, have attempted to address it in the last two versions of Ultimate Member, but they have reportedly failed to fully patch it. However, they did acknowledge the ongoing in-the-wild exploitation.

Site owners are advised to disable Ultimate Member to prevent exploitation of the vulnerability. They should also audit all administrator roles on their sites, to identify rogue accounts.

Related: Critical WordPress Plugin Vulnerabilities Impact Thousands of Sites

Related: Millions of WordPress Sites Patched Against Critical Jetpack Vulnerability

Related: WordPress Field Builder Plugin Vulnerability Exploited in Attacks Two Days After Patch

https://www.securityweek.com/200000-wordpress-sites-exposed-to-attacks-exploiting-flaw-in-ultimate-member-plugin/




Samsung Phone Flaws Added to CISA ‘Must Patch’ List Likely Exploited by Spyware Vendor

The US Cybersecurity and Infrastructure Security Agency (CISA) has added half a dozen flaws affecting Samsung smartphones to its Known Exploited Vulnerabilities Catalog, and they have all likely been exploited by a commercial spyware vendor.

CISA added eight new vulnerabilities to its catalog on Thursday, including two D-Link router and access point vulnerabilities exploited by a Mirai botnet variant. The six remaining security holes impact Samsung mobile devices and they were all patched by the technology giant in 2021.

The vulnerabilities include CVE-2021-25487, an out-of-bounds read in the modem interface driver that can lead to arbitrary code execution, fixed in October 2021. Samsung has classified the bug as ‘moderate’, but its NVD advisory says it’s ‘high severity’ based on CVSS score. 

The same October 2021 round of patches also addresses CVE-2021-25489, a low-severity format string bug in the modem interface driver that can lead to a DoS condition.

CISA also added CVE-2021-25394 and CVE-2021-25395, moderate-severity use-after-free bugs in the MFC charger driver. Both were fixed by Samsung in May 2021. 

The remaining two are CVE-2021-25371 a moderate-severity issue that can allow an attacker to load arbitrary ELF files inside the DSP driver, and CVE-2021-25372, a moderate-severity out-of-bounds access vulnerability in the same driver, both patched in March 2021. 

Samsung does not appear to have updated its old advisories to warn users about the exploitation of the vulnerabilities.

Advertisement. Scroll to continue reading.

There are no public reports describing exploitation of the Samsung mobile device vulnerabilities added to CISA’s ‘must-patch’ list this week. However, they have likely been exploited by a commercial spyware vendor.

Samsung and CISA recently warned users about CVE-2023-21492, a kernel pointer exposure issue related to log files that can allow a privileged local attacker to bypass the ASLR exploit mitigation technique.

Google, whose researchers discovered CVE-2023-21492, noted that the vulnerability has been known since 2021. 

In addition, in November 2022, Google disclosed the details of three similar Samsung phone vulnerabilities with 2021 CVEs that have been exploited by an unnamed spyware vendor against Android devices, including while they still had a zero-day status.

The three vulnerabilities disclosed in November 2022 were patched in March 2021. In addition, Google said at the time that it had been aware of half a dozen other Samsung vulnerabilities with 2021 CVE identifiers that have been exploited in attacks. This reinforces the theory that the flaws added by CISA this week to its catalog were exploited by spyware vendors whose activities have been monitored by Google. 

SecurityWeek has reached out to Google for confirmation. 

Related: Google Links Exploitation Frameworks to Spanish Spyware Vendor Variston

Related: New Samsung Message Guard Protects Mobile Devices Against Zero-Click Exploits

Related: Android Security Update Patches Kernel Vulnerability Exploited by Spyware Vendor

https://www.securityweek.com/samsung-phone-flaws-added-to-cisa-must-patch-list-likely-exploited-by-spyware-vendor/




MITRE Updates CWE Top 25 Most Dangerous Software Weaknesses

The MITRE Corporation has published an updated Common Weakness Enumeration (CWE) Top 25 Most Dangerous Software Weaknesses list to reflect the latest trends in the adversarial landscape.

The 2023 CWE Top 25 lists more common and impactful weaknesses leading to serious software vulnerabilities that are often exploited in malicious attacks to take over systems, steal information, or cause denial-of-service (DoS).

The main change at the top of this year’s list is the rise of use-after-free vulnerability types as the fourth most dangerous software weakness, up from the seventh position last year.

Additionally, OS command injection flaws (improper neutralization of special elements used in an OS command) went up one position, to reach the fifth place.

Out-of-bounds write and cross-site scripting (XSS) vulnerabilities continue to dominate the list, followed by SQL injection bugs.

Aside from various position changes at the middle of the list, it is worth noting that two vulnerability types have entered the 2023 CWE Top 25 this year, namely improper privilege management (now 22, up from 29), and incorrect authorization (24, up from 28).

Uncontrolled resource consumption and improper restriction of XML external entity reference (XXE) have dropped from the top 25 most dangerous vulnerabilities this year.

Advertisement. Scroll to continue reading.

According to the Cybersecurity and Infrastructure Security Agency (CISA), the 2023 CWE Top 25 has been updated with data for recent CVEs that were included in the agency’s Known Exploited Vulnerabilities (KEV) Catalog.

“The CWE Top 25 is calculated by analyzing public vulnerability data in the National Vulnerability Data (NVD) for root cause mappings to CWE weaknesses for the previous two calendar years,” CISA explains.

Throughout this summer, MITRE is planning the release of additional resources on CWE Top 25 methodology, vulnerability mapping trends, and other information to help developers and organizations understand and use the list more effectively.

Developers and security teams are advised to review the 2023 CWE Top 25 and evaluate and apply mitigations where possible.

Related: MITRE Publishes 2022 List of 25 Most Dangerous Vulnerabilities

Related: What We Learn from MITRE’s Most Dangerous Software Weaknesses List

Related: MITRE Publishes New List of Most Dangerous Software Weaknesses

https://www.securityweek.com/mitre-updates-cwe-top-25-most-dangerous-software-weaknesses/