<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:57:33.636176+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-25843</id>
    <title>EUVD-2026-25843</title>
    <updated>2026-10-03T10:57:33.705117+00:00</updated>
    <content>EUVD-2026-25843</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-25843"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-28100</id>
    <title>fkie_cve-2021-28100</title>
    <updated>2026-10-03T10:57:33.705154+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Priam uses File.createTempFile, which gives the permissions on that file -rw-r--r--. An attacker with read access to the local filesystem can read anything written there by the Priam process.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-28100"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f4jh-ww96-9h9j</id>
    <title>GHSA-f4jh-ww96-9h9j — Netflix/Priam: Temporary Directory Information Disclosure</title>
    <updated>2026-10-03T10:57:33.705187+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.netflix.priam:priam</p>
<p>### Impact</p>
<p>When `File.createTempFile` creates a file, the permissions on that file are -rw-r--r--. This means that other users can read the contents of these files after they are written, although they can not modify the contents. This allows for local information disclosure if these files contain sensitive information.</p>
<p>Vulnerable locations:
 - https://github.com/Netflix/Priam/blob/362660bb7ebddb0cfa756a282d94678f65af9f06/priam/src/main/java/com/netflix/priam/backup/MetaData.java#L106-L111
 - https://github.com/Netflix/Priam/blob/362660bb7ebddb0cfa756a282d94678f65af9f06/priam/src/main/java/com/netflix/priam/identity/DoubleRing.java#L109-L118
 - https://github.com/Netflix/Priam/blob/362660bb7ebddb0cfa756a282d94678f65af9f06/priam/src/main/java/com/netflix/priam/restore/PostRestoreHook.java#L80-L86</p>
<p>---</p>
<p>The custom CodeQL queries leveraged to find these this as well as their results can be found here:</p>
<p>https://lgtm.com/query/1543383251073929777/
https://lgtm.com/query/3142895023158674709/</p>
<p>## Official Disclosure</p>
<p>https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2021-002.md</p>
<p>## Fix</p>
<p>There are no fixed versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f4jh-ww96-9h9j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-28100</id>
    <title>gsd-2021-28100</title>
    <updated>2026-10-03T10:57:33.705227+00:00</updated>
    <content>gsd-2021-28100</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-28100"/>
  </entry>
</feed>
