<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T11:52:58.076035+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-53930</id>
    <title>cnvd-2021-53930</title>
    <updated>2026-10-08T11:52:58.140976+00:00</updated>
    <content>cnvd-2021-53930</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-53930"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-28074</id>
    <title>EUVD-2026-28074</title>
    <updated>2026-10-08T11:52:58.141021+00:00</updated>
    <content>EUVD-2026-28074</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-28074"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-32691</id>
    <title>fkie_cve-2021-32691</title>
    <updated>2026-10-08T11:52:58.141036+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apollos Apps is an open source platform for launching church-related apps. In Apollos Apps versions prior to 2.20.0, new user registrations are able to access anyone's account by only knowing their basic profile information (name, birthday, gender, etc). This includes all app functionality within the app, as well as any authenticated links to Rock-based webpages (such as giving and events). There is a patch in version 2.20.0. As a workaround, one can patch one's server by overriding the `create` data source method on the `People` class.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-32691"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r578-pj6f-r4ff</id>
    <title>GHSA-r578-pj6f-r4ff — Auto-merging Person Records Compromised</title>
    <updated>2026-10-08T11:52:58.141071+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @apollosproject/data-connector-rock</p>
<p>### Impact</p>
<p>New user registrations are able to access anyone's account by only knowing their basic profile information (name, birthday, gender, etc). This includes all app functionality within the app, as well as any authenticated links to Rock-based webpages (such as giving and events).</p>
<p>### Patches</p>
<p>We have released a security patch on v2.20.0. The solution was to create a duplicate person and then patch the new person with their profile details.</p>
<p>### Workarounds</p>
<p>If you do not wish to upgrade your app to the new version, you can patch your server by overriding the `create` data source method on the `People` class.</p>
<p>```js
  create = async (profile) =&gt; {
    const rockUpdateFields = this.mapApollosFieldsToRock(profile);
    // auto-merge functionality is compromised
    // we are creating a new user and patching them with profile details
    const id = await this.post('/People', {
      Gender: 0, // required by Rock. Listed first so it can be overridden.
      IsSystem: false, // required by rock
    });
    await this.patch(`/People/${id}`, {
      ...rockUpdateFields,
    });
    return id;
  };
```</p>
<p>### For more information
If you have any questions or comments about this advisory:
* Email us at [support@apollos.app](mailto:support@apollos.app)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r578-pj6f-r4ff"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-32691</id>
    <title>gsd-2021-32691</title>
    <updated>2026-10-08T11:52:58.141111+00:00</updated>
    <content>gsd-2021-32691</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-32691"/>
  </entry>
</feed>
