CVE-2023-35853: Code Injection
In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
suricatato a version that resolves this vulnerability.Fixed in 6.0.13 - Configuration
In Suricata 6.0.13+, disable Lua unless allow-rules is true in the security lua configuration section.
Suricata security Lua configuration allow-rules = true
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-35853.
What is the severity of CVE-2023-35853?
The severity of CVE-2023-35853 is critical with a score of 9.8.
What is the affected software?
The affected software is Suricata before version 6.0.13.
How can the vulnerability be exploited?
An adversary who controls an external source of Lua rules may be able to execute Lua code.
How is the vulnerability addressed in version 6.0.13 of Suricata?
The vulnerability is addressed in version 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section.