<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 21:53:18 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-00960</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-00960</link>
      <description>bdu:2021-00960</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-00960</guid>
    </item>
    <item>
      <title>certfr-2021-avi-951 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de
RedHat. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-951</link>
      <description>certfr-2021-avi-951</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-951</guid>
    </item>
    <item>
      <title>cnvd-2020-70849</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-70849</link>
      <description>cnvd-2020-70849</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-70849</guid>
    </item>
    <item>
      <title>EUVD-2026-43752</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-43752</link>
      <description>EUVD-2026-43752</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-43752</guid>
    </item>
    <item>
      <title>fkie_cve-2020-17521</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-17521</link>
      <description>&lt;p&gt;Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy&amp;#39;s implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy&amp;#39;s implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-17521</guid>
    </item>
    <item>
      <title>GHSA-rcjj-h6gh-jf3r — Information Disclosure in Apache Groovy</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rcjj-h6gh-jf3r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.codehaus.groovy:groovy, Maven: org.codehaus.groovy:groovy-all&lt;/p&gt;
&lt;p&gt;Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy&amp;#39;s implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.codehaus.groovy:groovy, Maven: org.codehaus.groovy:groovy-all&lt;/p&gt;
&lt;p&gt;Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy&amp;#39;s implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rcjj-h6gh-jf3r</guid>
    </item>
    <item>
      <title>gsd-2020-17521</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-17521</link>
      <description>gsd-2020-17521</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-17521</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:2367-1 — Security update for groovy</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:2367-1</link>
      <description>&lt;p&gt;Security update for groovy&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for groovy&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:2367-1</guid>
    </item>
    <item>
      <title>RHSA-2021:3205 — Red Hat Security Advisory: Red Hat Integration Camel-K 1.4 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3205</link>
      <description>&lt;p&gt;activemq: improper authentication allows MITM attack cxf: XSS via the styleSheetPath apache-flink: directory traversal attack allows remote file writing through the REST API groovy: OS temporary directory leads to information disclosure XStream: remote code execution due to insecure XML deserialization when relying on blocklists cron-utils: template injection allows attackers to inject arbitrary Java EL expressions leading to remote code execution XStream: Server-Side Forgery Request vulnerability can be activated when unmarshalling XStream: arbitrary file deletion on the local host when unmarshalling californium-core: DTLS - DoS vulnerability for certificate based handshakes undertow: special character in query results in server errors bouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible kotlin: vulnerable Java API was used for temporary file and folder creation which could result in information disclosure fabric8-kubernetes-client: vulnerable to a path traversal leading to integrity and availability compromise spring-web: (re)creating the temporary storage directory could result in  a privilege escalation within WebFlux application pdfbox: infinite loop while loading a crafted PDF file pdfbox: OutOfMemory-Exception while loading a crafted PDF file CXF: Denial of service vulnerability in parsing JSON via JsonMapObjectReaderWriter pdfbox: OutOfMemory-Exception while loading a crafted PDF file&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;activemq: improper authentication allows MITM attack cxf: XSS via the styleSheetPath apache-flink: directory traversal attack allows remote file writing through the REST API groovy: OS temporary directory leads to information disclosure XStream: remote code execution due to insecure XML deserialization when relying on blocklists cron-utils: template injection allows attackers to inject arbitrary Java EL expressions leading to remote code execution XStream: Server-Side Forgery Request vulnerability can be activated when unmarshalling XStream: arbitrary file deletion on the local host when unmarshalling californium-core: DTLS - DoS vulnerability for certificate based handshakes undertow: special character in query results in server errors bouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible kotlin: vulnerable Java API was used for temporary file and folder creation which could result in information disclosure fabric8-kubernetes-client: vulnerable to a path traversal leading to integrity and availability compromise spring-web: (re)creating the temporary storage directory could result in  a privilege escalation within WebFlux application pdfbox: infinite loop while loading a crafted PDF file pdfbox: OutOfMemory-Exception while loading a crafted PDF file CXF: Denial of service vulnerability in parsing JSON via JsonMapObjectReaderWriter pdfbox: OutOfMemory-Exception while loading a crafted PDF file&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3205</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:3917-1 — Security update for groovy</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:3917-1</link>
      <description>&lt;p&gt;Security update for groovy&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for groovy&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:3917-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-17521</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-17521</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: groovy, Ubuntu:Pro:16.04:LTS: groovy2, Ubuntu:18.04:LTS: groovy, Ubuntu:20.04:LTS: groovy, Ubuntu:22.04:LTS: groovy, Ubuntu:24.04:LTS: groovy, Ubuntu:25.10: groovy, Ubuntu:26.04:LTS: groovy&lt;/p&gt;
&lt;p&gt;Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy&amp;#39;s implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: groovy, Ubuntu:Pro:16.04:LTS: groovy2, Ubuntu:18.04:LTS: groovy, Ubuntu:20.04:LTS: groovy, Ubuntu:22.04:LTS: groovy, Ubuntu:24.04:LTS: groovy, Ubuntu:25.10: groovy, Ubuntu:26.04:LTS: groovy&lt;/p&gt;
&lt;p&gt;Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy&amp;#39;s implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-17521</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1375 — JFrog Artifactory: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1375</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in JFrog Artifactory ausnutzen, um seine Privilegien zu erweitern, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in JFrog Artifactory ausnutzen, um seine Privilegien zu erweitern, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1375</guid>
    </item>
  </channel>
</rss>
