<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T22:42:00.301901+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-00898</id>
    <title>bdu:2024-00898</title>
    <updated>2026-10-07T22:42:00.463064+00:00</updated>
    <content>bdu:2024-00898</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-00898"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0627</id>
    <title>certfr-2024-avi-0627 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-07T22:42:00.463102+00:00</updated>
    <content>certfr-2024-avi-0627</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0627"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-259870</id>
    <title>EUVD-2026-259870</title>
    <updated>2026-10-07T22:42:00.463122+00:00</updated>
    <content>EUVD-2026-259870</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-259870"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-43040</id>
    <title>fkie_cve-2023-43040</title>
    <updated>2026-10-07T22:42:00.463133+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access.  IBM X-Force ID:  266807.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-43040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fwhj-j6cr-5qw4</id>
    <title>GHSA-fwhj-j6cr-5qw4</title>
    <updated>2026-10-07T22:42:00.463162+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access.  IBM X-Force ID:  266807.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fwhj-j6cr-5qw4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-43040</id>
    <title>gsd-2023-43040</title>
    <updated>2026-10-07T22:42:00.463177+00:00</updated>
    <content>gsd-2023-43040</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-43040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-43040</id>
    <title>msrc_CVE-2023-43040 — IBM Spectrum Fusion HCI improper access control</title>
    <updated>2026-10-07T22:42:00.463187+00:00</updated>
    <content>msrc_CVE-2023-43040</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-43040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1761</id>
    <title>OESA-2023-1761 — ceph security update</title>
    <updated>2026-10-07T22:42:00.463203+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: ceph, openEuler:20.03-LTS-SP3: ceph, openEuler:22.03-LTS: ceph, openEuler:22.03-LTS-SP1: ceph, openEuler:22.03-LTS-SP2: ceph</p>
<p>Ceph is a massively scalable, open-source, distributed storage system that runs on commodity hardware and delivers object, block and file system storage.

Security Fix(es):

A flaw was found in rgw. This flaw allows an unprivileged user to write to any bucket(s) accessible by a given key if a POST&amp;apos;s form-data contains a key called &amp;apos;bucket&amp;apos; with a value matching the bucket&amp;apos;s name used to sign the request. This issue results in a user being able to upload to any bucket accessible by the specified access key as long as the bucket in the POST policy matches the bucket in the said POST form part.(CVE-2023-43040)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1761"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:5693</id>
    <title>RHSA-2023:5693 — Red Hat Security Advisory: Red Hat Ceph Storage 6.1 security, enhancement, and bug fix update</title>
    <updated>2026-10-07T22:42:00.463270+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bootstrap: Cross-site Scripting (XSS) in the data-target property of scrollspy bootstrap: XSS in the tooltip data-viewport attribute bootstrap: XSS in the affix configuration target property rgw: improperly verified POST keys ceph: RGW crash upon misconfigured CORS rule</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:5693"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-43040</id>
    <title>UBUNTU-CVE-2023-43040</title>
    <updated>2026-10-07T22:42:00.463293+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: ceph, Ubuntu:Pro:16.04:LTS: ceph, Ubuntu:Pro:18.04:LTS: ceph, Ubuntu:20.04:LTS: ceph, Ubuntu:22.04:LTS: ceph, Ubuntu:24.04:LTS: ceph</p>
<p>IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access.  IBM X-Force ID:  266807.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-43040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0331</id>
    <title>WID-SEC-W-2024-0331 — Red Hat Ceph Storage: Mehrere Schwachstellen</title>
    <updated>2026-10-07T22:42:00.463318+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Red Hat Ceph Storage ausnutzen, um Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0331"/>
  </entry>
</feed>
