<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:30:50.234044+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2017-09592</id>
    <title>cnvd-2017-09592</title>
    <updated>2026-10-02T21:30:50.245565+00:00</updated>
    <content>cnvd-2017-09592</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2017-09592"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-172380</id>
    <title>EUVD-2026-172380</title>
    <updated>2026-10-02T21:30:50.245602+00:00</updated>
    <content>EUVD-2026-172380</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-172380"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2017-2295</id>
    <title>fkie_cve-2017-2295</title>
    <updated>2026-10-02T21:30:50.245617+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, which would lead to remote code execution. This change constrains the format of data on the wire to PSON or safely decoded YAML.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2017-2295"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-988w-9qqw-43hr</id>
    <title>GHSA-988w-9qqw-43hr</title>
    <updated>2026-10-02T21:30:50.245647+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, which would lead to remote code execution. This change constrains the format of data on the wire to PSON or safely decoded YAML.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-988w-9qqw-43hr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2017-2295</id>
    <title>gsd-2017-2295</title>
    <updated>2026-10-02T21:30:50.245664+00:00</updated>
    <content>gsd-2017-2295</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2017-2295"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:0336</id>
    <title>RHSA-2018:0336 — Red Hat Security Advisory: Satellite 6.3 security, bug fix, and enhancement update</title>
    <updated>2026-10-02T21:30:50.245675+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rubygem-will_paginate: XSS vulnerabilities foreman: models with a 'belongs_to' association to an Organization do not verify association belongs to that Organization V8: integer overflow leading to buffer overflow in Zone::New foreman: inspect in a provisioning template exposes sensitive controller information pulp: Leakage of CA key in pulp-qpid-ssl-cfg pulp: Unsafe use of bash $RANDOM for NSS DB password and seed foreman: privilege escalation through Organization and Locations API foreman: Information disclosure in provisioning template previews foreman: inside discovery-debug, the root password is displayed in plaintext foreman: Persistent XSS in Foreman remote execution plugin foreman: Foreman information leak through unauthorized multiple_checkboxes helper foreman: Information leak through organizations and locations feature foreman: Stored XSS vulnerability in remote execution plugin foreman: Stored XSS in org/loc wizard foreman: Stored XSS via organization/location with HTML in name foreman-debug: missing obfuscation of sensitive information katello-debug: Possible symlink attacks due to use of predictable file names puppet: Unsafe YAML deserialization rubygem-hammer_cli: no verification of API server's SSL certificate foreman: Image password leak Interconnect: Denial of Service vulnerability in Red Hat JBoss AMQ Interconnect katello: SQL inject in errata-related REST API</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:0336"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2017:2113-1</id>
    <title>SUSE-SU-2017:2113-1 — Security update for puppet</title>
    <updated>2026-10-02T21:30:50.245719+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for puppet</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2017:2113-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-2295</id>
    <title>UBUNTU-CVE-2017-2295</title>
    <updated>2026-10-02T21:30:50.245734+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: puppet, Ubuntu:Pro:16.04:LTS: puppet</p>
<p>Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, which would lead to remote code execution. This change constrains the format of data on the wire to PSON or safely decoded YAML.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-2295"/>
  </entry>
</feed>
