<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:10:02.045015+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-04505</id>
    <title>bdu:2020-04505</title>
    <updated>2026-10-03T11:10:02.195016+00:00</updated>
    <content>bdu:2020-04505</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-04505"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-04130</id>
    <title>cnvd-2020-04130</title>
    <updated>2026-10-03T11:10:02.195079+00:00</updated>
    <content>cnvd-2020-04130</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-04130"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-55015</id>
    <title>EUVD-2026-55015</title>
    <updated>2026-10-03T11:10:02.195095+00:00</updated>
    <content>EUVD-2026-55015</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-55015"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-12423</id>
    <title>fkie_cve-2019-12423</title>
    <updated>2026-10-03T11:10:02.195106+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the service obtains the public key from a local keystore (JKS/PKCS12) by specifing the path of the keystore and the alias of the keystore entry. This case is not vulnerable. However it is also possible to obtain the keys from a JWK keystore file, by setting the configuration parameter "rs.security.keystore.type" to "jwk". For this case all keys are returned in this file "as is", including all private key and secret key credentials. This is an obvious security risk if the user has configured the signature keystore file with private or secret key credentials. From CXF 3.3.5 and 3.2.12, it is mandatory to specify an alias corresponding to the id of the key in the JWK file, and only this key is returned. In addition, any private key information is omitted by default. "oct" keys, which contain secret keys, are not returned at all.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-12423"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-42f2-f9vc-6365</id>
    <title>GHSA-42f2-f9vc-6365 — Private key leak in Apache CXF</title>
    <updated>2026-10-03T11:10:02.195143+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.cxf:apache-cxf, Maven: org.apache.cxf:cxf</p>
<p>Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the service obtains the public key from a local keystore (JKS/PKCS12) by specifing the path of the keystore and the alias of the keystore entry. This case is not vulnerable. However it is also possible to obtain the keys from a JWK keystore file, by setting the configuration parameter `rs.security.keystore.type` to `jwk`. For this case all keys are returned in this file &amp;quot;as is&amp;quot;, including all private key and secret key credentials. This is an obvious security risk if the user has configured the signature keystore file with private or secret key credentials. From CXF 3.3.5 and 3.2.12, it is mandatory to specify an alias corresponding to the id of the key in the JWK file, and only this key is returned. In addition, any private key information is omitted by default. `oct` keys, which contain secret keys, are not returned at all.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-42f2-f9vc-6365"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-12423</id>
    <title>gsd-2019-12423</title>
    <updated>2026-10-03T11:10:02.195177+00:00</updated>
    <content>gsd-2019-12423</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-12423"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:2058</id>
    <title>RHSA-2020:2058 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.8 on RHEL 6 security update</title>
    <updated>2026-10-03T11:10:02.195189+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jackson-mapper-asl: XML external entity similar to CVE-2016-3720 cxf: OpenId Connect token service does not properly validate the clientId cxf: reflected XSS in the services listing page Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain SmallRye: SecuritySupport class is incorrectly public and contains a static method to access the current threads context class loader Soteria: security identity corruption across concurrent threads undertow: AJP File Read/Inclusion Vulnerability undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass cryptacular: excessive memory allocation during a decode operation undertow: Memory exhaustion issue in HttpReadListener via "Expect: 100-continue" header undertow: invalid HTTP request with large chunk size</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:2058"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2123</id>
    <title>WID-SEC-W-2025-2123 — Red Hat JBoss Enterprise Application Platform: Mehrere Schwachstellen</title>
    <updated>2026-10-03T11:10:02.195244+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise Application Platform ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Angriff durchzuführen, einen Denial of Service Zustand herbeizuführen, Informationen offenzulegen oder Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2123"/>
  </entry>
</feed>
