<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T16:36:39.806349+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-06799</id>
    <title>bdu:2023-06799</title>
    <updated>2026-10-03T16:36:39.855644+00:00</updated>
    <content>bdu:2023-06799</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-06799"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-zookeeper-2023-44981</id>
    <title>BIT-zookeeper-2023-44981 — Apache ZooKeeper: Authorization bypass in SASL Quorum Peer Authentication</title>
    <updated>2026-10-03T16:36:39.855683+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: zookeeper</p>
<p>Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if it's missing, like 'eve@EXAMPLE.COM', the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. Quorum Peer authentication is not enabled by default.</p>
<p>Users are recommended to upgrade to version 3.9.1, 3.8.3, 3.7.2, which fixes the issue.</p>
<p>Alternately ensure the ensemble election/quorum communication is protected by a firewall as this will mitigate the issue.</p>
<p>See the documentation for more details on correct cluster administration.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-zookeeper-2023-44981"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0145</id>
    <title>certfr-2024-avi-0145 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-03T16:36:39.855725+00:00</updated>
    <content>certfr-2024-avi-0145</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0145"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ju62349</id>
    <title>Withdrawn: CLEANSTART-2026-JU62349 — Security fixes for CVE-2018-10237, CVE-2020-8908, CVE-2021-22569, CVE-2021-22570, CVE-2022-3171, CVE-2022-3509, CVE-202…</title>
    <updated>2026-10-03T16:36:39.855743+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: apache-hive</p>
<p>Multiple security vulnerabilities affect the apache-hive package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ju62349"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-233203</id>
    <title>EUVD-2026-233203</title>
    <updated>2026-10-03T16:36:39.855767+00:00</updated>
    <content>EUVD-2026-233203</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-233203"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-44981</id>
    <title>fkie_cve-2023-44981</title>
    <updated>2026-10-03T16:36:39.855778+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if it's missing, like 'eve@EXAMPLE.COM', the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. Quorum Peer authentication is not enabled by default.</p>
<p>Users are recommended to upgrade to version 3.9.1, 3.8.3, 3.7.2, which fixes the issue.</p>
<p>Alternately ensure the ensemble election/quorum communication is protected by a firewall as this will mitigate the issue.</p>
<p>See the documentation for more details on correct cluster administration.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-44981"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7286-pgfv-vxvh</id>
    <title>GHSA-7286-pgfv-vxvh — Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper</title>
    <updated>2026-10-03T16:36:39.855806+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.zookeeper:zookeeper</p>
<p>Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if it's missing, like 'eve@EXAMPLE.COM', the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. Quorum Peer authentication is not enabled by default.</p>
<p>Users are recommended to upgrade to version 3.9.1, 3.8.3, 3.7.2, which fixes the issue.</p>
<p>Alternately ensure the ensemble election/quorum communication is protected by a firewall as this will mitigate the issue.</p>
<p>See the documentation for more details on correct cluster administration.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7286-pgfv-vxvh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-44981</id>
    <title>gsd-2023-44981</title>
    <updated>2026-10-03T16:36:39.855835+00:00</updated>
    <content>gsd-2023-44981</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-44981"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:7678</id>
    <title>RHSA-2023:7678 — Red Hat Security Advisory: Red Hat AMQ Streams 2.6.0 release and security update</title>
    <updated>2026-10-03T16:36:39.855847+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>apache-ivy: XML External Entity vulnerability guava: insecure temporary directory creation JSON-java: parser confusion leads to OOM spring-boot: Security Bypass With Wildcard Pattern Matching on Cloud Foundry jose4j: Insecure iteration count setting bouncycastle: potential  blind LDAP injection attack using a self-signed certificate jetty: Improper validation of HTTP/1 content-length tomcat: Open Redirect vulnerability in FORM authentication gradle: Possible local text file exfiltration by XML External entity injection gradle: Incorrect permission assignment for symlinked files used in copy or archiving operations zookeeper: Authorization Bypass in Apache ZooKeeper</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:7678"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-44981</id>
    <title>UBUNTU-CVE-2023-44981</title>
    <updated>2026-10-03T16:36:39.855879+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: zookeeper, Ubuntu:20.04:LTS: zookeeper, Ubuntu:22.04:LTS: zookeeper</p>
<p>Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if it's missing, like 'eve@EXAMPLE.COM', the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. Quorum Peer authentication is not enabled by default. Users are recommended to upgrade to version 3.9.1, 3.8.3, 3.7.2, which fixes the issue. Alternately ensure the ensemble election/quorum communication is protected by a firewall as this will mitigate the issue. See the documentation for more details on correct cluster administration.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-44981"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3070</id>
    <title>WID-SEC-W-2023-3070 — Red Hat JBoss A-MQ: Mehrere Schwachstellen</title>
    <updated>2026-10-03T16:36:39.855906+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss A-MQ ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen, Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3070"/>
  </entry>
</feed>
