<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:37:21.197871+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-02260</id>
    <title>bdu:2024-02260</title>
    <updated>2026-10-03T10:37:21.296336+00:00</updated>
    <content>bdu:2024-02260</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-02260"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-21124</id>
    <title>EUVD-2026-21124</title>
    <updated>2026-10-03T10:37:21.296373+00:00</updated>
    <content>EUVD-2026-21124</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-21124"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3827</id>
    <title>fkie_cve-2021-3827</title>
    <updated>2026-10-03T10:37:21.296387+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an attacker can bypass the MFA authentication by sending a SOAP request with an AuthnRequest and Authorization header with the user's credentials. The highest threat from this vulnerability is to confidentiality and integrity.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-3827"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4pc7-vqv5-5r3v</id>
    <title>GHSA-4pc7-vqv5-5r3v — ECP SAML binding bypasses authentication flows</title>
    <updated>2026-10-03T10:37:21.296418+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-saml-core</p>
<p>### Description
A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior an attacker can bypass the MFA authentication by sending a SOAP request with an AuthnRequest and Authorization header with the user's credentials. The highest threat from this vulnerability is to confidentiality and integrity.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4pc7-vqv5-5r3v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-3827</id>
    <title>gsd-2021-3827</title>
    <updated>2026-10-03T10:37:21.296442+00:00</updated>
    <content>gsd-2021-3827</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-3827"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:0151</id>
    <title>RHSA-2022:0151 — Red Hat Security Advisory: Red Hat Single Sign-On 7.5.1 security update on RHEL 7</title>
    <updated>2026-10-03T10:37:21.296453+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>keycloak-server-spi-private: ECP SAML binding bypasses authentication flows Keycloak: Incorrect authorization allows unpriviledged users to create other users resteasy: Error message exposes endpoint class information xml-security: XPath Transform abuse allows for information disclosure</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:0151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0794</id>
    <title>WID-SEC-W-2024-0794 — Dell ECS: Mehrere Schwachstellen</title>
    <updated>2026-10-03T10:37:21.296473+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Dell ECS ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0794"/>
  </entry>
</feed>
