<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:16:55 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-02260</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-02260</link>
      <description>bdu:2020-02260</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-02260</guid>
    </item>
    <item>
      <title>cnvd-2019-41646</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-41646</link>
      <description>cnvd-2019-41646</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-41646</guid>
    </item>
    <item>
      <title>EUVD-2026-53429</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-53429</link>
      <description>EUVD-2026-53429</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-53429</guid>
    </item>
    <item>
      <title>fkie_cve-2019-10174</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-10174</link>
      <description>&lt;p&gt;A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan&amp;#39;s privileges. The attacker can use reflection to introduce new, malicious behavior into the application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan&amp;#39;s privileges. The attacker can use reflection to introduce new, malicious behavior into the application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-10174</guid>
    </item>
    <item>
      <title>GHSA-h47x-2j37-fw5m — Use of Externally-Controlled Input to Select Classes or Code in Infinispan</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h47x-2j37-fw5m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.infinispan:infinispan-core&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan&amp;#39;s privileges. The attacker can use reflection to introduce new, malicious behavior into the application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.infinispan:infinispan-core&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan&amp;#39;s privileges. The attacker can use reflection to introduce new, malicious behavior into the application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h47x-2j37-fw5m</guid>
    </item>
    <item>
      <title>gsd-2019-10174</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-10174</link>
      <description>gsd-2019-10174</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-10174</guid>
    </item>
    <item>
      <title>OESA-2024-1667 — infinispan security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1667</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: infinispan, openEuler:20.03-LTS-SP4: infinispan, openEuler:22.03-LTS: infinispan, openEuler:22.03-LTS-SP1: infinispan, openEuler:22.03-LTS-SP2: infinispan, openEuler:22.03-LTS-SP3: infinispan&lt;/p&gt;
&lt;p&gt;Infinispan is an extremely scalable, highly available data grid platform - 100% open source, and written in Java. The purpose of Infinispan is to expose a data structure that is highly concurrent, designed ground-up to make the most of modern multi-processor/multi-core architectures while at the same time providing distributed cache capabilities.  At its core Infinispan exposes a Cache interface which extends java.util.Map. It is also optionally is backed by a peer-to-peer network architecture to distribute state efficiently around a data grid.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan&amp;amp;apos;s privileges. The attacker can use reflection to introduce new, malicious behavior into the application.(CVE-2019-10174)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: infinispan, openEuler:20.03-LTS-SP4: infinispan, openEuler:22.03-LTS: infinispan, openEuler:22.03-LTS-SP1: infinispan, openEuler:22.03-LTS-SP2: infinispan, openEuler:22.03-LTS-SP3: infinispan&lt;/p&gt;
&lt;p&gt;Infinispan is an extremely scalable, highly available data grid platform - 100% open source, and written in Java. The purpose of Infinispan is to expose a data structure that is highly concurrent, designed ground-up to make the most of modern multi-processor/multi-core architectures while at the same time providing distributed cache capabilities.  At its core Infinispan exposes a Cache interface which extends java.util.Map. It is also optionally is backed by a peer-to-peer network architecture to distribute state efficiently around a data grid.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan&amp;amp;apos;s privileges. The attacker can use reflection to introduce new, malicious behavior into the application.(CVE-2019-10174)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1667</guid>
    </item>
    <item>
      <title>RHSA-2019:3901 — Red Hat Security Advisory: Red Hat OpenShift Application Runtimes Vert.x 3.8.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2019:3901</link>
      <description>&lt;p&gt;infinispan: invokeAccessibly method from ReflectionUtil class allows to invoke private methods jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution jackson-databind: default typing mishandling leading to remote code execution netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.* jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource jackson-databind: Serialization gadgets in classes of the ehcache package&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;infinispan: invokeAccessibly method from ReflectionUtil class allows to invoke private methods jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution jackson-databind: default typing mishandling leading to remote code execution netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.* jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource jackson-databind: Serialization gadgets in classes of the ehcache package&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2019:3901</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1926 — Red Hat JBoss Enterprise Application Platform: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1926</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise Application Platform auf Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen, einen Denial-of-Service-Zustand zu erzeugen, vertrauliche Informationen preiszugeben, Dateien und Daten zu manipulieren oder Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise Application Platform auf Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen, einen Denial-of-Service-Zustand zu erzeugen, vertrauliche Informationen preiszugeben, Dateien und Daten zu manipulieren oder Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1926</guid>
    </item>
  </channel>
</rss>
