In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section.
[
{
"source": "https://github.com/oisf/suricata/commit/b95bbcc66db526ffcc880eb439dbe8abc87a81da",
"target": {
"file": "src/detect-lua.c"
},
"deprecated": false,
"id": "CVE-2023-35853-4cb74c9c",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"103305860143753160792491287364709395789",
"235129584418255779798626245926161842464",
"293693393145250041927974542757688195874",
"263275719835584498844336486386064445902",
"297203217210655163813541935474860239733",
"121731090351737341739739412241062912324",
"182847789500480247703452451693903526470",
"169203383410590033556495563816597827213"
]
},
"signature_type": "Line"
},
{
"source": "https://github.com/oisf/suricata/commit/b95bbcc66db526ffcc880eb439dbe8abc87a81da",
"target": {
"function": "DetectLuaSetup",
"file": "src/detect-lua.c"
},
"deprecated": false,
"id": "CVE-2023-35853-bc8b8fb4",
"signature_version": "v1",
"digest": {
"length": 3090.0,
"function_hash": "304649107609855633561903920416861928796"
},
"signature_type": "Function"
},
{
"source": "https://github.com/oisf/suricata/commit/b95bbcc66db526ffcc880eb439dbe8abc87a81da",
"target": {
"function": "LuaMatchTest01",
"file": "src/detect-lua.c"
},
"deprecated": false,
"id": "CVE-2023-35853-f14c3566",
"signature_version": "v1",
"digest": {
"length": 3945.0,
"function_hash": "230516447770906724568909213276965772559"
},
"signature_type": "Function"
}
]