<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:20:07.373487+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-wildfly-2025-23367</id>
    <title>BIT-wildfly-2025-23367 — Org.wildfly.core:wildfly-server: wildfly improper rbac permission</title>
    <updated>2026-10-03T04:20:07.586011+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: wildfly</p>
<p>A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. 
The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-wildfly-2025-23367"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0671</id>
    <title>certfr-2026-avi-0671 — De multiples vulnérabilités ont été découvertes dans les produits NetApp. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-03T04:20:07.586080+00:00</updated>
    <content>certfr-2026-avi-0671</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0671"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-371663</id>
    <title>EUVD-2026-371663</title>
    <updated>2026-10-03T04:20:07.586102+00:00</updated>
    <content>EUVD-2026-371663</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-371663"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-23367</id>
    <title>fkie_cve-2025-23367</title>
    <updated>2026-10-03T04:20:07.586114+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. 
The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-23367"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qr6x-62gq-4ccp</id>
    <title>GHSA-qr6x-62gq-4ccp — WildFly improper RBAC permission</title>
    <updated>2026-10-03T04:20:07.586138+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.wildfly.core:wildfly-server</p>
<p>A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.</p>
<p>### Impact
Standalone server (Domain mode is not affected) with use access control enabled with RBAC provider can be suspended or resumed by unauthorized users. When a server is suspended, the server will stop receiving user requests. The resume handle does the opposite; it will cause a suspended server to start accepting user requests.</p>
<p>### Patches
Fixed in [WildFly Core 27.0.1.Final](https://github.com/wildfly/wildfly-core/releases/tag/27.0.1.Final)</p>
<p>### Workarounds
No workaround available</p>
<p>### References
See also: https://issues.redhat.com/browse/WFCORE-7153</p>
<p>### Acknowledgements
The WildFly project would like to thank Claudia Bartolini (TIM S.p.A), Marco Ventura (TIM S.p.A), and Massimiliano Brolli (TIM S.p.A) for reporting this issue. https://www.gruppotim.it/it/footer/red-team.html</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qr6x-62gq-4ccp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:3465</id>
    <title>RHSA-2025:3465 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.21 security update</title>
    <updated>2026-10-03T04:20:07.586172+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>netty: Denial of Service attack on windows app using Netty hornetq-core-client: Arbitrarily overwrite files or access sensitive information org.wildfly.core:wildfly-server: Wildfly improper RBAC permission io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine netty: Denial of Service attack on windows app using Netty commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:3465"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0230</id>
    <title>WID-SEC-W-2025-0230 — Red Hat WildFly: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T04:20:07.586206+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat WildFly ausnutzen, um einen Denial of Service herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0230"/>
  </entry>
</feed>
