cvedb.io
CVE-2023-35853
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2023-06-19T04:15:11.287 · Last modified 2026-06-17T06:05:20.557

Summary

In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section.

Affected products

oisf — suricata

Does this affect you?

Add your gear to cvedb and we'll alert you only when oisf ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.