<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:43:18.058993+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-05326</id>
    <title>bdu:2023-05326</title>
    <updated>2026-10-04T00:43:18.294570+00:00</updated>
    <content>bdu:2023-05326</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-05326"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0567</id>
    <title>certfr-2023-avi-0567 — De multiples vulnérabilités ont été découvertes dans Oracle WebLogic.
Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-04T00:43:18.294617+00:00</updated>
    <content>certfr-2023-avi-0567</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0567"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-25877</id>
    <title>EUVD-2026-25877</title>
    <updated>2026-10-04T00:43:18.294637+00:00</updated>
    <content>EUVD-2026-25877</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-25877"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-28168</id>
    <title>fkie_cve-2021-28168</title>
    <updated>2026-10-04T00:43:18.294650+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-28168"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c43q-5hpj-4crv</id>
    <title>GHSA-c43q-5hpj-4crv — Local information disclosure via system temporary directory</title>
    <updated>2026-10-04T00:43:18.294681+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.glassfish.jersey.core:jersey-common</p>
<p>## Impact
Eclipse Jersey 2.28 - 2.33 and Eclipse Jersey 3.0.0 - 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the `File.createTempFile` which creates a file inside of the system temporary directory with the permissions: `-rw-r--r--`. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.</p>
<p>## Workaround</p>
<p>This issue can be mitigated by manually setting the `java.io.tmpdir` system property when launching the JVM.</p>
<p>## Patches</p>
<p>Jersey 2.34 and 3.0.2 forward sets the correct permissions on the temporary file created by Jersey.</p>
<p>### References
 
 - https://github.com/eclipse-ee4j/jersey/pull/4712
 - [CWE-378: Creation of Temporary File With Insecure Permissions](https://cwe.mitre.org/data/definitions/378.html)
 - [CWE-379: Creation of Temporary File in Directory with Insecure Permissions](https://cwe.mitre.org/data/definitions/379.html)</p>
<p>## Similar Vulnerabilities</p>
<p>Similar, but not the same:</p>
<p>- JUnit 4 - https://github.com/junit-team/junit4/security/advisories/GHSA-269g-pwp5-87pp
 - Google Guava - https://github.com/google/guava/issues/4011
 - Apache Ant - https://nvd.nist.gov/vuln/detail/CVE-2020-1945
 - JetBrains Kotlin Compiler - https://nvd.nist.gov/vuln/detail/CVE-2020-15824
 - Eclipse Jetty - https://github.com/eclipse/jetty.project/security/advisories/GHSA-g3wg-6mcf-8jj6</p>
<p>---</p>
<p>Original Disclosure:</p>
<p>&gt; Hello…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c43q-5hpj-4crv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-28168</id>
    <title>gsd-2021-28168</title>
    <updated>2026-10-04T00:43:18.294737+00:00</updated>
    <content>gsd-2021-28168</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-28168"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1181</id>
    <title>OESA-2021-1181 — jersey security update</title>
    <updated>2026-10-04T00:43:18.294749+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: jersey</p>
<p>Jersey is the open source JAX-RS (JSR 311) production quality Reference Implementation for building RESTful Web services.

Security Fix(es):

Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.(CVE-2021-28168)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1181"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:3225</id>
    <title>RHSA-2021:3225 — Red Hat Security Advisory: Red Hat AMQ Streams 1.8.0 release and security update</title>
    <updated>2026-10-04T00:43:18.294773+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>snakeyaml: Billion laughs attack via alias feature netty: Information disclosure via the local system temporary directory netty: possible request smuggling in HTTP/2 due missing validation netty: Request smuggling via content-length header json-smart: uncaught exception may lead to crash or information disclosure jetty: Symlink directory exposes webapp directory contents jetty: Ambiguous paths can access WEB-INF jetty: Resource exhaustion when receiving an invalid large TLS frame jersey: Local information disclosure via system temporary directory jetty: requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directory apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6 jetty: SessionListener can prevent a session from being invalidated breaking logout</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:3225"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1807</id>
    <title>WID-SEC-W-2023-1807 — Oracle Fusion Middleware: Mehrere Schwachstellen</title>
    <updated>2026-10-04T00:43:18.294808+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1807"/>
  </entry>
</feed>
