<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:08:02 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-25843</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-25843</link>
      <description>EUVD-2026-25843</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-25843</guid>
    </item>
    <item>
      <title>fkie_cve-2021-28100</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-28100</link>
      <description>&lt;p&gt;Priam uses File.createTempFile, which gives the permissions on that file -rw-r--r--. An attacker with read access to the local filesystem can read anything written there by the Priam process.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Priam uses File.createTempFile, which gives the permissions on that file -rw-r--r--. An attacker with read access to the local filesystem can read anything written there by the Priam process.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-28100</guid>
    </item>
    <item>
      <title>GHSA-f4jh-ww96-9h9j — Netflix/Priam: Temporary Directory Information Disclosure</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f4jh-ww96-9h9j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.netflix.priam:priam&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;When `File.createTempFile` creates a file, the permissions on that file are -rw-r--r--. This means that other users can read the contents of these files after they are written, although they can not modify the contents. This allows for local information disclosure if these files contain sensitive information.&lt;/p&gt;
&lt;p&gt;Vulnerable locations:
 - https://github.com/Netflix/Priam/blob/362660bb7ebddb0cfa756a282d94678f65af9f06/priam/src/main/java/com/netflix/priam/backup/MetaData.java#L106-L111
 - https://github.com/Netflix/Priam/blob/362660bb7ebddb0cfa756a282d94678f65af9f06/priam/src/main/java/com/netflix/priam/identity/DoubleRing.java#L109-L118
 - https://github.com/Netflix/Priam/blob/362660bb7ebddb0cfa756a282d94678f65af9f06/priam/src/main/java/com/netflix/priam/restore/PostRestoreHook.java#L80-L86&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;The custom CodeQL queries leveraged to find these this as well as their results can be found here:&lt;/p&gt;
&lt;p&gt;https://lgtm.com/query/1543383251073929777/
https://lgtm.com/query/3142895023158674709/&lt;/p&gt;
&lt;p&gt;## Official Disclosure&lt;/p&gt;
&lt;p&gt;https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2021-002.md&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;There are no fixed versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.netflix.priam:priam&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;When `File.createTempFile` creates a file, the permissions on that file are -rw-r--r--. This means that other users can read the contents of these files after they are written, although they can not modify the contents. This allows for local information disclosure if these files contain sensitive information.&lt;/p&gt;
&lt;p&gt;Vulnerable locations:
 - https://github.com/Netflix/Priam/blob/362660bb7ebddb0cfa756a282d94678f65af9f06/priam/src/main/java/com/netflix/priam/backup/MetaData.java#L106-L111
 - https://github.com/Netflix/Priam/blob/362660bb7ebddb0cfa756a282d94678f65af9f06/priam/src/main/java/com/netflix/priam/identity/DoubleRing.java#L109-L118
 - https://github.com/Netflix/Priam/blob/362660bb7ebddb0cfa756a282d94678f65af9f06/priam/src/main/java/com/netflix/priam/restore/PostRestoreHook.java#L80-L86&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;The custom CodeQL queries leveraged to find these this as well as their results can be found here:&lt;/p&gt;
&lt;p&gt;https://lgtm.com/query/1543383251073929777/
https://lgtm.com/query/3142895023158674709/&lt;/p&gt;
&lt;p&gt;## Official Disclosure&lt;/p&gt;
&lt;p&gt;https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2021-002.md&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;There are no fixed versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f4jh-ww96-9h9j</guid>
    </item>
    <item>
      <title>gsd-2021-28100</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-28100</link>
      <description>gsd-2021-28100</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-28100</guid>
    </item>
  </channel>
</rss>
