<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:06:13.452574+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-112117</id>
    <title>EUVD-2026-112117</title>
    <updated>2026-10-03T22:06:13.557604+00:00</updated>
    <content>EUVD-2026-112117</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-112117"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2012-3865</id>
    <title>fkie_cve-2012-3865</title>
    <updated>2026-10-03T22:06:13.557643+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a .. (dot dot) in a node name.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2012-3865"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g89m-3wjw-h857</id>
    <title>GHSA-g89m-3wjw-h857 — Puppet vulnerable to Path Traversal</title>
    <updated>2026-10-03T22:06:13.557677+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: puppet</p>
<p>Directory traversal vulnerability in `lib/puppet/reports/store.rb` in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a `..` (dot dot) in a node name.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g89m-3wjw-h857"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2012-3865</id>
    <title>gsd-2012-3865</title>
    <updated>2026-10-03T22:06:13.557709+00:00</updated>
    <content>gsd-2012-3865</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2012-3865"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10581-1</id>
    <title>openSUSE-SU-2024:10581-1 — ruby2.2-rubygem-puppet-3.8.7-2.2 on GA media</title>
    <updated>2026-10-03T22:06:13.557731+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby2.2-rubygem-puppet-3.8.7-2.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10581-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2012:1542</id>
    <title>RHSA-2012:1542 — Red Hat Security Advisory: CloudForms Commons 1.1 security update</title>
    <updated>2026-10-03T22:06:13.557775+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>puppet: Filebucket arbitrary file read puppet: Filebucket denial of service puppet: Filebucket arbitrary code execution rubygem-mail: directory traversal rubygem-mail: arbitrary command execution when using exim or sendmail from commandline rubygem-actionpack: Unsafe query generation rubygem-activerecord: SQL injection when processing nested query paramaters rubygem-actionpack: Unsafe query generation (a different flaw than CVE-2012-2660) rubygem-activerecord: SQL injection when processing nested query paramaters (a different flaw than CVE-2012-2661) rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest rubygem-actionpack: potential XSS vulnerability in select_tag prompt rubygem-actionpack: potential XSS vulnerability rubygem-actionpack: XSS Vulnerability in strip_tags puppet: authenticated clients allowed to read arbitrary files from the puppet master puppet: authenticated clients allowed to delete arbitrary files on the puppet master puppet: insufficient validation of agent names in CN of SSL certificate requests</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2012:1542"/>
  </entry>
</feed>
