<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T13:40:07.498563+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:2293</id>
    <title>ALSA-2023:2293 — Moderate: pki-core security, bug fix, and enhancement update</title>
    <updated>2026-10-06T13:40:07.665395+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: idm-pki-acme, AlmaLinux:9: idm-pki-base, AlmaLinux:9: idm-pki-ca, AlmaLinux:9: idm-pki-est, AlmaLinux:9: idm-pki-java, AlmaLinux:9: idm-pki-kra, AlmaLinux:9: idm-pki-server, AlmaLinux:9: idm-pki-tools, AlmaLinux:9: python3-idm-pki</p>
<p>The Public Key Infrastructure (PKI) Core contains fundamental packages required by AlmaLinux Certificate System.</p>
<p>Security Fix(es):</p>
<p>* pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field (CVE-2022-2393)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:2293"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-12368</id>
    <title>EUVD-2026-12368</title>
    <updated>2026-10-06T13:40:07.665477+00:00</updated>
    <content>EUVD-2026-12368</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-12368"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-2393</id>
    <title>fkie_cve-2022-2393</title>
    <updated>2026-10-06T13:40:07.665495+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-2393"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hjh3-jq28-5qcc</id>
    <title>GHSA-hjh3-jq28-5qcc</title>
    <updated>2026-10-06T13:40:07.665519+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hjh3-jq28-5qcc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-2393</id>
    <title>gsd-2022-2393</title>
    <updated>2026-10-06T13:40:07.665535+00:00</updated>
    <content>gsd-2022-2393</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-2393"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:7077</id>
    <title>RHSA-2022:7077 — Red Hat Security Advisory: Red Hat Certificate System 9.7 CVE bug fix update</title>
    <updated>2026-10-06T13:40:07.665547+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:7077"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:7086</id>
    <title>RHSA-2022:7086 — Red Hat Security Advisory: pki-core security update</title>
    <updated>2026-10-06T13:40:07.665566+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:7086"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2393</id>
    <title>UBUNTU-CVE-2022-2393</title>
    <updated>2026-10-06T13:40:07.665582+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: dogtag-pki, Ubuntu:Pro:18.04:LTS: dogtag-pki, Ubuntu:Pro:20.04:LTS: dogtag-pki, Ubuntu:Pro:22.04:LTS: dogtag-pki</p>
<p>A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2393"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0706</id>
    <title>WID-SEC-W-2022-0706 — Red Hat Enterprise Linux: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-06T13:40:07.665605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer aus dem angrenzenden Netzwerk kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0706"/>
  </entry>
</feed>
