<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:52:34.681888+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-nats-2022-24450</id>
    <title>BIT-nats-2022-24450</title>
    <updated>2026-10-03T09:52:34.716799+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: nats</p>
<p>NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-nats-2022-24450"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0199</id>
    <title>certfr-2026-avi-0199 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-03T09:52:34.716861+00:00</updated>
    <content>certfr-2026-avi-0199</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-14187</id>
    <title>EUVD-2026-14187</title>
    <updated>2026-10-03T09:52:34.716883+00:00</updated>
    <content>EUVD-2026-14187</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-14187"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24450</id>
    <title>fkie_cve-2022-24450</title>
    <updated>2026-10-03T09:52:34.716896+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-24450"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g6w6-r76c-28j7</id>
    <title>GHSA-g6w6-r76c-28j7 — Incorrect Authorization in NATS nats-server</title>
    <updated>2026-10-03T09:52:34.716919+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/nats-io/nats-server/v2, Go: github.com/nats-io/nats-streaming-server</p>
<p>(This advisory is canonically &lt;https://advisories.nats.io/CVE/CVE-2022-24450.txt&gt;)</p>
<p>## Problem Description</p>
<p>NATS nats-server through 2022-02-04 has Incorrect Access Control, with unchecked ability for clients to authorize into any account, because of a coding error in a long-extant experimental feature.</p>
<p>A client crafting the initial protocol-level handshake could, with valid credentials for any account, specify a target account and switch into it immediately.  This includes any other tenant, and includes the System account which controls nats-server core operations.</p>
<p>For deployments not using multi-tenancy through NATS Accounts, there is still a vulnerability: normal users are able to choose to be in the System account.</p>
<p>An experimental feature to provide dynamically provisioned sandbox accounts was designed to allow a server administrator to turn on an option to allow clients to dynamically request a brand new account inline at connection time.  This feature went nowhere, but lived on in the code and was used by a number of tests; support was never added to any client libraries or to the documentation.</p>
<p>A bug in handling the feature meant that if someone did in fact have valid account credentials, then they could specify any other existing account and they would be assigned into that account.</p>
<p>Release 2.7.2 of nats-server removes the feature.
Because of the lack of client support and absence from protocol documentation, we feel this is safe operationally as well as the saf…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g6w6-r76c-28j7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-24450</id>
    <title>gsd-2022-24450</title>
    <updated>2026-10-03T09:52:34.716962+00:00</updated>
    <content>gsd-2022-24450</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-24450"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:0735</id>
    <title>RHSA-2022:0735 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.4.2 security updates and bug fixes</title>
    <updated>2026-10-03T09:52:34.716975+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes nodejs-json-schema: Prototype pollution vulnerability fastify-static: open redirect via an URL with double slash followed by a domain moby: `docker cp` allows unexpected chmod of host file moby: data directory contains subdirectories with insufficiently restricted permissions, which could lead to directory traversal golang.org/x/crypto: empty plaintext packet causes panic containerd: Unprivileged pod may bind mount any privileged regular file on disk minio: user privilege escalation in AddUser() admin API node-fetch: exposure of sensitive information to an unauthorized actor nats-server: misusing the "dynamically provisioned sandbox accounts" feature  authenticated user can obtain the privileges of the System account</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:0735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0235</id>
    <title>WID-SEC-W-2022-0235 — Red Hat Advanced Cluster Management: Mehrere Schwachstellen ermöglichen Privilegieneskalation</title>
    <updated>2026-10-03T09:52:34.717011+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Advanced Cluster Management ausnutzen, um seine Privilegien zu erhöhen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0235"/>
  </entry>
</feed>
