<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:41:44.285664+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-05833</id>
    <title>bdu:2024-05833</title>
    <updated>2026-10-03T14:41:44.621248+00:00</updated>
    <content>bdu:2024-05833</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-05833"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-1055</id>
    <title>certfr-2023-avi-1055 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-03T14:41:44.621298+00:00</updated>
    <content>certfr-2023-avi-1055</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-1055"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-hp29225</id>
    <title>CLEANSTART-2026-HP29225 — Security fix for CVE-2023-36479 applied in: apache-hive 4.0.0-r1</title>
    <updated>2026-10-03T14:41:44.621318+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: apache-hive</p>
<p>Security vulnerability affects the apache-hive package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-hp29225"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-245075</id>
    <title>EUVD-2026-245075</title>
    <updated>2026-10-03T14:41:44.621350+00:00</updated>
    <content>EUVD-2026-245075</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-245075"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-36479</id>
    <title>fkie_cve-2023-36479</title>
    <updated>2026-10-03T14:41:44.621363+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-36479"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3gh6-v5v9-6v9j</id>
    <title>GHSA-3gh6-v5v9-6v9j — Jetty vulnerable to errant command quoting in CGI Servlet</title>
    <updated>2026-10-03T14:41:44.621389+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.eclipse.jetty:jetty-servlets, Maven: org.eclipse.jetty.ee10:jetty-ee10-servlets, Maven: org.eclipse.jetty.ee9:jetty-ee9-servlets, Maven: org.eclipse.jetty.ee8:jetty-ee8-servlets</p>
<p>If a user sends a request to a `org.eclipse.jetty.servlets.CGI` Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. For example, if a request references a binary called file” name “here, the escaping algorithm will generate the command line string “file” name “here”, which will invoke the binary named file, not the one that the user requested.</p>
<p>```java
if (execCmd.length() &gt; 0 &amp;&amp; execCmd.charAt(0) != '"' &amp;&amp; execCmd.contains(" "))
execCmd = "\"" + execCmd + "\"";
```</p>
<p>### Exploit Scenario
The cgi-bin directory contains a binary named exec and a subdirectory named exec” commands, which contains a file called bin1. The user sends to the CGI servlet a request for the filename exec” commands/bin1. This request will pass the file existence check on lines 194 through 205. The servlet will add quotation marks around this filename, resulting in the command line string “exec” commands/bin1”. When this string is passed to Runtime.exec, instead of executing the bin1 binary, the server will execute the exec
binary with the argument commands/file1”. In addition to being incorrect, this behavior may bypass alias checks, and it may cause other unintended…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3gh6-v5v9-6v9j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-36479</id>
    <title>gsd-2023-36479</title>
    <updated>2026-10-03T14:41:44.621440+00:00</updated>
    <content>gsd-2023-36479</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-36479"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-2268</id>
    <title>OESA-2024-2268 — jetty security update</title>
    <updated>2026-10-03T14:41:44.621460+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: jetty</p>
<p>%global desc \ Jetty is a 100% Java HTTP Server and Servlet Container. This means that you\ do not need to configure and run a separate web server (like Apache) in order\ to use Java, servlets and JSPs to generate dynamic content. Jetty is a fully\ featured web server for static and dynamic content. Unlike separate\ server/container solutions, this means that your web server and web\ application run in the same process, without interconnection overheads\ and complications. Furthermore, as a pure java component, Jetty can be simply\ included in your application for demonstration, distribution or deployment.\ Jetty is available on all Java supported platforms. \ %global extdesc \\ \ This package contains

Security Fix(es):

Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotated with `@MultipartConfig`) that call `HttpServletRequest.getParameter()` or `HttpServletRequest.getParts()` may cause `OutOfMemoryError` when the client sends a multipart request with a part that has a name but no filename and very large content. This happens even with the default settings of `fileSizeThreshold=0` which should stream the whole part content to disk. An attacker client may send a large multipart request and cause the server to throw `OutOfMemoryError`. However, the server may be able to recover after the `OutOfMemoryError` and continue its service -- although it may take some time. This issue has been patched in versions…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-2268"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13329-1</id>
    <title>openSUSE-SU-2024:13329-1 — jetty-annotations-9.4.53-1.1 on GA media</title>
    <updated>2026-10-03T14:41:44.621498+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jetty-annotations-9.4.53-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13329-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:7247</id>
    <title>RHSA-2023:7247 — Red Hat Security Advisory: Red Hat Fuse 7.12.1 release and security update</title>
    <updated>2026-10-03T14:41:44.621520+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>undertow: OutOfMemoryError due to @MultipartConfig handling okio: GzipSource class improper exception handling spring-security-webflux: path wildcard leads to security bypass jetty: hpack header values cause denial of service in http/2 jetty: Improper addition of quotation marks to user inputs in CgiServlet apache-avro: Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK jetty: Improper validation of HTTP/1 content-length jetty: OpenId Revoked authentication allows one request tomcat: FileUpload: DoS due to accumulation of temporary files on Windows tomcat: improper cleaning of recycled objects could lead to information leak HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) tomcat: incorrectly parsed http trailer headers can cause request smuggling activemq-openwire: OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:7247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-36479</id>
    <title>UBUNTU-CVE-2023-36479</title>
    <updated>2026-10-03T14:41:44.621556+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: jetty, Ubuntu:16.04:LTS: jetty</p>
<p>Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-36479"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2359</id>
    <title>WID-SEC-W-2023-2359 — Eclipse Jetty: Mehrere Schwachstellen</title>
    <updated>2026-10-03T14:41:44.621580+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter authentifizierter Angreifer kann mehrere Schwachstellen in Eclipse Jetty ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen oder einen HTTP-Cache-Poison-Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2359"/>
  </entry>
</feed>
