In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section.
2023-06-19T04:15:11.287
2024-12-11T17:15:13.037
Modified
CVSSv3.1: 9.8 (CRITICAL)