In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.
https://www.debian.org/security/2023/dsa-5321
https://support.apple.com/kb/HT213758
https://security.netapp.com/advisory/ntap-20230127-0015/
https://security.gentoo.org/glsa/202305-12
https://lists.debian.org/debian-lts-announce/2023/01/msg00012.html
http://seclists.org/fulldisclosure/2023/Aug/21
http://packetstormsecurity.com/files/172509/Sudoedit-Extra-Arguments-Privilege-Escalation.html
http://packetstormsecurity.com/files/171644/sudo-1.9.12p1-Privilege-Escalation.html
https://github.com/ZeroPathAI/zeropath-ctf
https://github.com/ValeuDoamne/CVE-2023-22809
https://github.com/spidoman/CVE-2023-22809-automated-python-exploits
https://github.com/Spydomain/CVE-2023-22809-automated-python-exploits
https://github.com/ucsb-seclab/CVEX-records
https://github.com/D0rDa4aN919/CVE-2023-22809-Exploiter
https://github.com/laxmiyamkolu/SUDO-privilege-escalation
https://github.com/CKevens/CVE-2023-22809-sudo-POC
https://github.com/RESOLUTE-ATTACK/CVES
https://github.com/Zeyad-Azima/Remedy4me
https://github.com/n3m1sys/CVE-2023-22809-sudoedit-privesc
https://github.com/n3m1dotsys/CVE-2023-22809-sudoedit-privesc
https://www.synacktiv.com/sites/default/files/2023-01/sudo-CVE-2023-22809.pdf