<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:53:24.591194+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-04278</id>
    <title>bdu:2022-04278</title>
    <updated>2026-10-02T19:53:24.836776+00:00</updated>
    <content>bdu:2022-04278</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-04278"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1059</id>
    <title>certfr-2022-avi-1059 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T19:53:24.836824+00:00</updated>
    <content>certfr-2022-avi-1059</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-1059"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-49973</id>
    <title>cnvd-2022-49973</title>
    <updated>2026-10-02T19:53:24.836844+00:00</updated>
    <content>cnvd-2022-49973</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-49973"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-17740</id>
    <title>EUVD-2026-17740</title>
    <updated>2026-10-02T19:53:24.836856+00:00</updated>
    <content>EUVD-2026-17740</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-17740"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-33980</id>
    <title>fkie_cve-2022-33980</title>
    <updated>2026-10-02T19:53:24.836867+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Configuration 2.8.0, which disables the problematic interpolators by default.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-33980"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xj57-8qj4-c4m6</id>
    <title>GHSA-xj57-8qj4-c4m6 — Code injection in Apache Commons Configuration</title>
    <updated>2026-10-02T19:53:24.836903+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.commons:commons-configuration2</p>
<p>Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Configuration 2.8.0, which disables the problematic interpolators by default.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xj57-8qj4-c4m6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-33980</id>
    <title>gsd-2022-33980</title>
    <updated>2026-10-02T19:53:24.836934+00:00</updated>
    <content>gsd-2022-33980</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-33980"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13259-1</id>
    <title>openSUSE-SU-2024:13259-1 — apache-commons-configuration2-2.9.0-1.1 on GA media</title>
    <updated>2026-10-02T19:53:24.836946+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>apache-commons-configuration2-2.9.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13259-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:6916</id>
    <title>RHSA-2022:6916 — Red Hat Security Advisory: Red Hat AMQ Broker 7.10.1 release and security update</title>
    <updated>2026-10-02T19:53:24.836963+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation netty: world readable temporary file containing sensitive data apache-commons-configuration: Apache Commons Configuration insecure interpolation defaults activemq-artemis: AMQ Broker web console HTML Injection</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:6916"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-33980</id>
    <title>UBUNTU-CVE-2022-33980</title>
    <updated>2026-10-02T19:53:24.836983+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: commons-configuration2, Ubuntu:20.04:LTS: commons-configuration2, Ubuntu:22.04:LTS: commons-configuration2</p>
<p>Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Configuration 2.8.0, which disables the problematic interpolators by default.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-33980"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0590</id>
    <title>WID-SEC-W-2022-0590 — Apache Commons: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-02T19:53:24.837012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann eine Schwachstelle in Apache Commons ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0590"/>
  </entry>
</feed>
