<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:30:47 +0000</lastBuildDate>
    <item>
      <title>cnvd-2017-34869</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-34869</link>
      <description>cnvd-2017-34869</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-34869</guid>
    </item>
    <item>
      <title>EUVD-2026-76971</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-76971</link>
      <description>EUVD-2026-76971</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-76971</guid>
    </item>
    <item>
      <title>fkie_cve-2017-12167</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-12167</link>
      <description>&lt;p&gt;It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-12167</guid>
    </item>
    <item>
      <title>GHSA-5gp7-3qfp-8548</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5gp7-3qfp-8548</link>
      <description>&lt;p&gt;It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5gp7-3qfp-8548</guid>
    </item>
    <item>
      <title>gsd-2017-12167</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-12167</link>
      <description>gsd-2017-12167</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-12167</guid>
    </item>
    <item>
      <title>RHSA-2017:3454 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.1.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2017:3454</link>
      <description>&lt;p&gt;Artemis: Deserialization of untrusted input vulnerability eap: HTTP header injection / response splitting EAP7 Privilege escalation when managing domain including earlier version slaves EAP7: Internal IP address disclosed on redirect when request header Host field is not set undertow: Long URL proxy request lead to java.nio.BufferOverflowException and DoS EAP: Sensitive data can be exposed at the server level in domain mode admin-cli: Potential EAP resource starvation DOS attack via GET requests for server log files jboss: jbossas: unsafe chown of server.log in jboss init script allows privilege escalation wildfly: ParseState headerValuesCache can be exploited to fill heap with garbage wildfly: Arbitrary file read via path traversal undertow: HTTP Request smuggling vulnerability due to permitting invalid characters in HTTP requests undertow: IO thread DoS via unclean Websocket closing jackson-databind: Deserialization vulnerability via readValue method of ObjectMapper hibernate-validator: Privilege escalation when running under the security manager undertow: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666) undertow: improper whitespace parsing leading to potential HTTP request smuggling EAP-7: Wrong privileges on multiple property files&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Artemis: Deserialization of untrusted input vulnerability eap: HTTP header injection / response splitting EAP7 Privilege escalation when managing domain including earlier version slaves EAP7: Internal IP address disclosed on redirect when request header Host field is not set undertow: Long URL proxy request lead to java.nio.BufferOverflowException and DoS EAP: Sensitive data can be exposed at the server level in domain mode admin-cli: Potential EAP resource starvation DOS attack via GET requests for server log files jboss: jbossas: unsafe chown of server.log in jboss init script allows privilege escalation wildfly: ParseState headerValuesCache can be exploited to fill heap with garbage wildfly: Arbitrary file read via path traversal undertow: HTTP Request smuggling vulnerability due to permitting invalid characters in HTTP requests undertow: IO thread DoS via unclean Websocket closing jackson-databind: Deserialization vulnerability via readValue method of ObjectMapper hibernate-validator: Privilege escalation when running under the security manager undertow: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666) undertow: improper whitespace parsing leading to potential HTTP request smuggling EAP-7: Wrong privileges on multiple property files&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2017:3454</guid>
    </item>
  </channel>
</rss>
