<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 07:04:23 +0000</lastBuildDate>
    <item>
      <title>BIT-cassandra-2020-13946</title>
      <link>https://cve.radiocsirt.org/vuln/bit-cassandra-2020-13946</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: cassandra&lt;/p&gt;
&lt;p&gt;In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: cassandra&lt;/p&gt;
&lt;p&gt;In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-cassandra-2020-13946</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0537 — De multiples vulnérabilités ont été découvertes dans les produits
Juniper. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0537</link>
      <description>certfr-2023-avi-0537</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0537</guid>
    </item>
    <item>
      <title>cnvd-2020-50259</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-50259</link>
      <description>cnvd-2020-50259</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-50259</guid>
    </item>
    <item>
      <title>EUVD-2026-42080</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-42080</link>
      <description>EUVD-2026-42080</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-42080</guid>
    </item>
    <item>
      <title>fkie_cve-2020-13946</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-13946</link>
      <description>&lt;p&gt;In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-13946</guid>
    </item>
    <item>
      <title>GHSA-24ww-mc5x-xc43 — Man-in-the-middle attack in Apache Cassandra</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-24ww-mc5x-xc43</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.cassandra:cassandra-all&lt;/p&gt;
&lt;p&gt;In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.cassandra:cassandra-all&lt;/p&gt;
&lt;p&gt;In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-24ww-mc5x-xc43</guid>
    </item>
    <item>
      <title>gsd-2020-13946</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-13946</link>
      <description>gsd-2020-13946</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-13946</guid>
    </item>
    <item>
      <title>RHSA-2021:0811 — Red Hat Security Advisory: Red Hat Integration Tech-Preview 3 Camel K security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:0811</link>
      <description>&lt;p&gt;cassandra: allows manipulation of the RMI registry to perform a MITM attack and capture user names and passwords used to access the JMX interface apache-httpclient: incorrect handling of malformed authority component in request URIs jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cassandra: allows manipulation of the RMI registry to perform a MITM attack and capture user names and passwords used to access the JMX interface apache-httpclient: incorrect handling of malformed authority component in request URIs jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:0811</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1737 — Juniper Patchday Juli 2023</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1737</link>
      <description>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer oder lokaler Angreifer kann mehrere Schwachstellen in verschiedenen Juniper Produkten ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen und seine Privilegien zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer oder lokaler Angreifer kann mehrere Schwachstellen in verschiedenen Juniper Produkten ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen und seine Privilegien zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1737</guid>
    </item>
  </channel>
</rss>
