<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T17:57:03.848639+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-342685</id>
    <title>EUVD-2026-342685</title>
    <updated>2026-10-06T17:57:03.900365+00:00</updated>
    <content>EUVD-2026-342685</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-342685"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-67439</id>
    <title>fkie_cve-2026-67439</title>
    <updated>2026-10-06T17:57:03.900416+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the service/internal/api/api.go StartActionAndWait and StartActionByGetAndWait endpoints return full LogEntry output after execution without enforcing the logs permission, allowing a user with exec permission but logs:false to read action output. This issue is fixed in version 3000.17.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-67439"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jm28-2wcr-qf3h</id>
    <title>GHSA-jm28-2wcr-qf3h — OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output</title>
    <updated>2026-10-06T17:57:03.900463+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/OliveTin/OliveTin</p>
<p>## Summary</p>
<p>The synchronous execution RPCs `StartActionAndWait` and `StartActionByGetAndWait` return the full `LogEntry` for the just-executed action without checking whether the caller is allowed to read that action's logs.</p>
<p>OliveTin's ACL model separates `exec` from `logs`. A deployment can intentionally allow a user to run an action while denying access to its historical or live output. That separation is enforced in `GetLogs`, `GetActionLogs`, `ExecutionStatus`, and `EventStream`, but it is not enforced in the synchronous `...AndWait` endpoints.</p>
<p>As a result, any user who can execute an action through these endpoints can read the action output immediately even when the action's ACL explicitly sets `logs:false`.</p>
<p>## Details</p>
<p>OliveTin defines separate per-action permissions:</p>
<p>```go
// service/internal/config/config.go
type PermissionsList struct {
    View bool `koanf:"view"`
    Exec bool `koanf:"exec"`
    Logs bool `koanf:"logs"`
    Kill bool `koanf:"kill"`
}
```</p>
<p>The normal log and streaming paths correctly enforce `logs` permission:</p>
<p>```go
// service/internal/api/api.go
func (api *oliveTinAPI) isLogEntryAllowed(e *executor.InternalLogEntry, user *authpublic.AuthenticatedUser) bool {
    if user == nil || !isValidLogEntry(e) {
        return false
    }
    return acl.IsAllowedLogs(api.cfg, user, e.Binding.Action)
}
```</p>
<p>That check is used by:</p>
<p>- `GetLogs`
- `GetActionLogs`
- `ExecutionStatus`
- `EventStream`</p>
<p>However, the synchronous execution endpoints directly retu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jm28-2wcr-qf3h"/>
  </entry>
</feed>
