<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:54:45.233780+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:9058</id>
    <title>ALSA-2022:9058 — Important: prometheus-jmx-exporter security update</title>
    <updated>2026-10-02T16:54:45.551959+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: prometheus-jmx-exporter, AlmaLinux:8: prometheus-jmx-exporter-openjdk11, AlmaLinux:8: prometheus-jmx-exporter-openjdk17, AlmaLinux:8: prometheus-jmx-exporter-openjdk8</p>
<p>Prometheus JMX Exporter is a JMX to Prometheus exporter: a collector that can be configured to scrape and expose MBeans of a JMX target.</p>
<p>Security Fix(es):</p>
<p>* SnakeYaml: Constructor Deserialization Remote Code Execution (CVE-2022-1471)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:9058"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-00013</id>
    <title>bdu:2023-00013</title>
    <updated>2026-10-02T16:54:45.552060+00:00</updated>
    <content>bdu:2023-00013</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-00013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0287</id>
    <title>certfr-2023-avi-0287 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à u…</title>
    <updated>2026-10-02T16:54:45.552079+00:00</updated>
    <content>certfr-2023-avi-0287</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</id>
    <title>Withdrawn: CLEANSTART-2026-CI66802 — Security fixes for CVE-2015-2104, CVE-2020-8908, CVE-2021-21295, CVE-2021-21409, CVE-2021-37136, CVE-2022-1471, CVE-202…</title>
    <updated>2026-10-02T16:54:45.552096+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: cassandra-fips</p>
<p>Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-245037</id>
    <title>EUVD-2026-245037</title>
    <updated>2026-10-02T16:54:45.552122+00:00</updated>
    <content>EUVD-2026-245037</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-245037"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-1471</id>
    <title>fkie_cve-2022-1471</title>
    <updated>2026-10-02T16:54:45.552134+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-1471"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mjmj-j48q-9wg2</id>
    <title>GHSA-mjmj-j48q-9wg2 — SnakeYaml Constructor Deserialization Remote Code Execution</title>
    <updated>2026-10-02T16:54:45.552158+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.yaml:snakeyaml</p>
<p>### Summary
SnakeYaml's `Constructor` class, which inherits from `SafeConstructor`, allows
any type be deserialized given the following line:</p>
<p>new Yaml(new Constructor(TestDataClass.class)).load(yamlContent);</p>
<p>Types do not have to match the types of properties in the
target class. A `ConstructorException` is thrown, but only after a malicious
payload is deserialized.</p>
<p>### Severity
High, lack of type checks during deserialization allows remote code execution.</p>
<p>### Proof of Concept
Execute `bash run.sh`. The PoC uses Constructor to deserialize a payload
for RCE. RCE is demonstrated by using a payload which performs a http request to
http://127.0.0.1:8000.</p>
<p>Example output of successful run of proof of concept:</p>
<p>```
$ bash run.sh</p>
<p>[+] Downloading snakeyaml if needed
[+] Starting mock HTTP server on 127.0.0.1:8000 to demonstrate RCE
nc: no process found
[+] Compiling and running Proof of Concept, which a payload that sends a HTTP request to mock web server.
[+] An exception is expected.
Exception:
Cannot create property=payload for JavaBean=Main$TestDataClass@3cbbc1e0
 in 'string', line 1, column 1:
    payload: !!javax.script.ScriptEn ... 
    ^
Can not set java.lang.String field Main$TestDataClass.payload to javax.script.ScriptEngineManager
 in 'string', line 1, column 10:
    payload: !!javax.script.ScriptEngineManag ... 
             ^</p>
<p>at org.yaml.snakeyaml.constructor.Constructor$ConstructMapping.constructJavaBean2ndStep(Constructor.java:291)
	at org.yaml.snakeyaml.constru…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mjmj-j48q-9wg2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-1471</id>
    <title>gsd-2022-1471</title>
    <updated>2026-10-02T16:54:45.552209+00:00</updated>
    <content>gsd-2022-1471</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-1471"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13151-1</id>
    <title>openSUSE-SU-2024:13151-1 — jackson-dataformat-csv-2.15.2-1.1 on GA media</title>
    <updated>2026-10-02T16:54:45.552221+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jackson-dataformat-csv-2.15.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13151-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2023:0030</id>
    <title>RHBA-2023:0030 — Red Hat Bug Fix Advisory: updated RHEL-8 based Middleware Containers container images</title>
    <updated>2026-10-02T16:54:45.552238+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SnakeYaml: Constructor Deserialization Remote Code Execution</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2023:0030"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-1471</id>
    <title>UBUNTU-CVE-2022-1471</title>
    <updated>2026-10-02T16:54:45.552254+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: snakeyaml, Ubuntu:Pro:16.04:LTS: snakeyaml, Ubuntu:Pro:18.04:LTS: snakeyaml, Ubuntu:Pro:20.04:LTS: snakeyaml, Ubuntu:22.04:LTS: snakeyaml, Ubuntu:24.04:LTS: snakeyaml</p>
<p>SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-1471"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2347</id>
    <title>WID-SEC-W-2022-2347 — Red Hat Enterprise Linux: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-02T16:54:45.552296+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux und Oracle Linux ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2347"/>
  </entry>
</feed>
