<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:28:52 +0000</lastBuildDate>
    <item>
      <title>BIT-solr-2020-9492</title>
      <link>https://cve.radiocsirt.org/vuln/bit-solr-2020-9492</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: solr&lt;/p&gt;
&lt;p&gt;In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0 to 3.1.3, and 2.0.0 to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: solr&lt;/p&gt;
&lt;p&gt;In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0 to 3.1.3, and 2.0.0 to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-solr-2020-9492</guid>
    </item>
    <item>
      <title>certfr-2021-avi-545 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Elles permettent à un attaquant de provoquer une…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-545</link>
      <description>certfr-2021-avi-545</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-545</guid>
    </item>
    <item>
      <title>cnvd-2021-11848</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-11848</link>
      <description>cnvd-2021-11848</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-11848</guid>
    </item>
    <item>
      <title>EUVD-2026-39161</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-39161</link>
      <description>EUVD-2026-39161</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-39161</guid>
    </item>
    <item>
      <title>fkie_cve-2020-9492</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-9492</link>
      <description>&lt;p&gt;In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-9492</guid>
    </item>
    <item>
      <title>GHSA-f8vc-wfc8-hxqh — Improper Privilege Management in Apache Hadoop</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f8vc-wfc8-hxqh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.hadoop:hadoop-common&lt;/p&gt;
&lt;p&gt;In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.hadoop:hadoop-common&lt;/p&gt;
&lt;p&gt;In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f8vc-wfc8-hxqh</guid>
    </item>
    <item>
      <title>gsd-2020-9492</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-9492</link>
      <description>gsd-2020-9492</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-9492</guid>
    </item>
    <item>
      <title>OESA-2021-1201 — hadoop security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1201</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: hadoop&lt;/p&gt;
&lt;p&gt;Apache Hadoop is a framework that allows for the distributed processing of large data sets across clusters of computers using simple programming models. It is designed to scale up from single servers to thousands of machines, each offering local computation and storage.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.(CVE-2020-9492)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: hadoop&lt;/p&gt;
&lt;p&gt;Apache Hadoop is a framework that allows for the distributed processing of large data sets across clusters of computers using simple programming models. It is designed to scale up from single servers to thousands of machines, each offering local computation and storage.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.(CVE-2020-9492)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1201</guid>
    </item>
    <item>
      <title>RHSA-2022:5606 — Red Hat Security Advisory: Red Hat Integration Camel Extensions for Quarkus 2.7 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:5606</link>
      <description>&lt;p&gt;hadoop: WebHDFS client might send SPNEGO authorization header lz4: memory corruption due to an integer overflow bug caused by memmove argument elasticsearch: executing async search improperly stores HTTP headers leading to information disclosure elasticsearch: Document disclosure flaw in the Elasticsearch suggester elasticsearch: Document disclosure flaw when Document or Field Level Security is used jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients xstream: Injecting highly recursive collections or maps can cause a DoS quarkus: privilege escalation vulnerability with RestEasy Reactive scope leakage in Quarkus&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;hadoop: WebHDFS client might send SPNEGO authorization header lz4: memory corruption due to an integer overflow bug caused by memmove argument elasticsearch: executing async search improperly stores HTTP headers leading to information disclosure elasticsearch: Document disclosure flaw in the Elasticsearch suggester elasticsearch: Document disclosure flaw when Document or Field Level Security is used jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients xstream: Injecting highly recursive collections or maps can cause a DoS quarkus: privilege escalation vulnerability with RestEasy Reactive scope leakage in Quarkus&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:5606</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0227 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0227</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um seine Privilegien zu erweitern, Administratorrechte zu erlangen, beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um seine Privilegien zu erweitern, Administratorrechte zu erlangen, beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0227</guid>
    </item>
  </channel>
</rss>
