<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:40:33.755502+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:4706</id>
    <title>ALSA-2023:4706 — Important: subscription-manager security update</title>
    <updated>2026-10-03T01:40:33.930243+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: dnf-plugin-subscription-manager, AlmaLinux:8: python3-cloud-what, AlmaLinux:8: python3-subscription-manager-rhsm, AlmaLinux:8: python3-syspurpose, AlmaLinux:8: subscription-manager, AlmaLinux:8: subscription-manager-migration, AlmaLinux:8: subscription-manager-plugin-ostree, AlmaLinux:8: subscription-manager-rhsm-certificates</p>
<p>The subscription-manager packages provide programs and libraries to allow users to manage subscriptions and yum repositories from the AlmaLinux entitlement platform.</p>
<p>Security Fix(es):</p>
<p>* subscription-manager: inadequate authorization of com.AlmaLinux.RHSM1 D-Bus interface allows local users to modify configuration (CVE-2023-3899)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:4706"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-04878</id>
    <title>bdu:2023-04878</title>
    <updated>2026-10-03T01:40:33.930311+00:00</updated>
    <content>bdu:2023-04878</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-04878"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0950</id>
    <title>certfr-2023-avi-0950 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;Juniper Secure Analytics&lt;/span&gt;. Certaines d'…</title>
    <updated>2026-10-03T01:40:33.930328+00:00</updated>
    <content>certfr-2023-avi-0950</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0950"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-261415</id>
    <title>EUVD-2026-261415</title>
    <updated>2026-10-03T01:40:33.930344+00:00</updated>
    <content>EUVD-2026-261415</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-261415"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-3899</id>
    <title>fkie_cve-2023-3899</title>
    <updated>2026-10-03T01:40:33.930354+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a low-privileged local user could tamper with the state of the registration, by unregistering the system or by changing the current entitlements. This flaw allows an attacker to set arbitrary configuration directives for /etc/rhsm/rhsm.conf, which can be abused to cause a local privilege escalation to an unconfined root.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-3899"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wp8h-m67c-cxpw</id>
    <title>GHSA-wp8h-m67c-cxpw</title>
    <updated>2026-10-03T01:40:33.930377+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a low-privileged local user could tamper with the state of the registration, by unregistering the system or by changing the current entitlements. This flaw allows an attacker to set arbitrary configuration directives for /etc/rhsm/rhsm.conf, which can be abused to cause a local privilege escalation to an unconfined root.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wp8h-m67c-cxpw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-3899</id>
    <title>gsd-2023-3899</title>
    <updated>2026-10-03T01:40:33.930394+00:00</updated>
    <content>gsd-2023-3899</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-3899"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:4701</id>
    <title>RHSA-2023:4701 — Red Hat Security Advisory: subscription-manager security update</title>
    <updated>2026-10-03T01:40:33.930404+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>subscription-manager: inadequate authorization of com.redhat.RHSM1 D-Bus interface allows local users to modify configuration</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:4701"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2118</id>
    <title>WID-SEC-W-2023-2118 — Red Hat Enterprise Linux (subscription-manager): Schwachstelle ermöglicht Privilegieneskalation</title>
    <updated>2026-10-03T01:40:33.930421+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um seine Privilegien zu erhöhen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2118"/>
  </entry>
</feed>
