<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:21:23 +0000</lastBuildDate>
    <item>
      <title>cnvd-2019-44531</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-44531</link>
      <description>cnvd-2019-44531</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-44531</guid>
    </item>
    <item>
      <title>EUVD-2026-49759</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-49759</link>
      <description>EUVD-2026-49759</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-49759</guid>
    </item>
    <item>
      <title>fkie_cve-2019-3875</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-3875</link>
      <description>&lt;p&gt;A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The CRL are often available over the network through unsecured protocols (&amp;#39;http&amp;#39; or &amp;#39;ldap&amp;#39;) and hence the caller should verify the signature and possibly the certification path. Keycloak currently doesn&amp;#39;t validate signatures on CRL, which can result in a possibility of various attacks like man-in-the-middle.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The CRL are often available over the network through unsecured protocols (&amp;#39;http&amp;#39; or &amp;#39;ldap&amp;#39;) and hence the caller should verify the signature and possibly the certification path. Keycloak currently doesn&amp;#39;t validate signatures on CRL, which can result in a possibility of various attacks like man-in-the-middle.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-3875</guid>
    </item>
    <item>
      <title>GHSA-38cg-gg9j-q9j9 — Improper Certificate Validation and Insufficient Verification of Data Authenticity in Keycloak</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-38cg-gg9j-q9j9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-core&lt;/p&gt;
&lt;p&gt;A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The CRL are often available over the network through unsecured protocols (&amp;#39;http&amp;#39; or &amp;#39;ldap&amp;#39;) and hence the caller should verify the signature and possibly the certification path. Keycloak currently doesn&amp;#39;t validate signatures on CRL, which can result in a possibility of various attacks like man-in-the-middle.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-core&lt;/p&gt;
&lt;p&gt;A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The CRL are often available over the network through unsecured protocols (&amp;#39;http&amp;#39; or &amp;#39;ldap&amp;#39;) and hence the caller should verify the signature and possibly the certification path. Keycloak currently doesn&amp;#39;t validate signatures on CRL, which can result in a possibility of various attacks like man-in-the-middle.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-38cg-gg9j-q9j9</guid>
    </item>
    <item>
      <title>gsd-2019-3875</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-3875</link>
      <description>gsd-2019-3875</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-3875</guid>
    </item>
    <item>
      <title>RHSA-2019:1456 — Red Hat Security Advisory: Red Hat Single Sign-On 7.3.2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2019:1456</link>
      <description>&lt;p&gt;bootstrap: XSS in the data-target attribute bootstrap: Cross-site Scripting (XSS) in the data-target property of scrollspy bootstrap: XSS in the tooltip data-viewport attribute bootstrap: XSS in the affix configuration target property picketlink: reflected XSS in SAMLRequest via RelayState parameter picketlink: URL injection via xinclude parameter keycloak: missing signatures validation on CRL used to verify client certificates undertow: leak credentials to log files UndertowLogger.REQUEST_LOGGER.undertowRequestFailed bootstrap: XSS in the tooltip or popover data-template attribute keycloak: Node.js adapter internal NBF can be manipulated leading to DoS. jquery: Prototype pollution in object&amp;#39;s prototype leading to denial of service, remote code execution, or property injection&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bootstrap: XSS in the data-target attribute bootstrap: Cross-site Scripting (XSS) in the data-target property of scrollspy bootstrap: XSS in the tooltip data-viewport attribute bootstrap: XSS in the affix configuration target property picketlink: reflected XSS in SAMLRequest via RelayState parameter picketlink: URL injection via xinclude parameter keycloak: missing signatures validation on CRL used to verify client certificates undertow: leak credentials to log files UndertowLogger.REQUEST_LOGGER.undertowRequestFailed bootstrap: XSS in the tooltip or popover data-template attribute keycloak: Node.js adapter internal NBF can be manipulated leading to DoS. jquery: Prototype pollution in object&amp;#39;s prototype leading to denial of service, remote code execution, or property injection&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2019:1456</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1947 — Red Hat Single Sign On: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1947</link>
      <description>&lt;p&gt;Ein  Angreifer kann mehrere Schwachstellen in Red Hat Single Sign On ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, einen Denial of Service Zustand hervorzurufen, Informationen auszuspähen, Sicherheitsvorkehrungen zu umgehen oder beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein  Angreifer kann mehrere Schwachstellen in Red Hat Single Sign On ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, einen Denial of Service Zustand hervorzurufen, Informationen auszuspähen, Sicherheitsvorkehrungen zu umgehen oder beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1947</guid>
    </item>
  </channel>
</rss>
