<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 01:45:39 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-05326</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-05326</link>
      <description>bdu:2023-05326</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-05326</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0567 — De multiples vulnérabilités ont été découvertes dans Oracle WebLogic.
Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0567</link>
      <description>certfr-2023-avi-0567</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0567</guid>
    </item>
    <item>
      <title>EUVD-2026-25877</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-25877</link>
      <description>EUVD-2026-25877</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-25877</guid>
    </item>
    <item>
      <title>fkie_cve-2021-28168</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-28168</link>
      <description>&lt;p&gt;Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-28168</guid>
    </item>
    <item>
      <title>GHSA-c43q-5hpj-4crv — Local information disclosure via system temporary directory</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c43q-5hpj-4crv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.glassfish.jersey.core:jersey-common&lt;/p&gt;
&lt;p&gt;## Impact
Eclipse Jersey 2.28 - 2.33 and Eclipse Jersey 3.0.0 - 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the `File.createTempFile` which creates a file inside of the system temporary directory with the permissions: `-rw-r--r--`. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.&lt;/p&gt;
&lt;p&gt;## Workaround&lt;/p&gt;
&lt;p&gt;This issue can be mitigated by manually setting the `java.io.tmpdir` system property when launching the JVM.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;Jersey 2.34 and 3.0.2 forward sets the correct permissions on the temporary file created by Jersey.&lt;/p&gt;
&lt;p&gt;### References
 
 - https://github.com/eclipse-ee4j/jersey/pull/4712
 - [CWE-378: Creation of Temporary File With Insecure Permissions](https://cwe.mitre.org/data/definitions/378.html)
 - [CWE-379: Creation of Temporary File in Directory with Insecure Permissions](https://cwe.mitre.org/data/definitions/379.html)&lt;/p&gt;
&lt;p&gt;## Similar Vulnerabilities&lt;/p&gt;
&lt;p&gt;Similar, but not the same:&lt;/p&gt;
&lt;p&gt;- JUnit 4 - https://github.com/junit-team/junit4/security/advisories/GHSA-269g-pwp5-87pp
 - Google Guava - https://github.com/google/guava/issues/4011
 - Apache Ant - https://nvd.nist.gov/vuln/detail/CVE-2020-1945
 - JetBrains Kotlin Compiler - https://nvd.nist.gov/vuln/detail/CVE-2020-15824
 - Eclipse Jetty - https://github.com/eclipse/jetty.project/security/advisories/GHSA-g3wg-6mcf-8jj6&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;Original Disclosure:&lt;/p&gt;
&lt;p&gt;&amp;gt; Hello…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.glassfish.jersey.core:jersey-common&lt;/p&gt;
&lt;p&gt;## Impact
Eclipse Jersey 2.28 - 2.33 and Eclipse Jersey 3.0.0 - 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the `File.createTempFile` which creates a file inside of the system temporary directory with the permissions: `-rw-r--r--`. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.&lt;/p&gt;
&lt;p&gt;## Workaround&lt;/p&gt;
&lt;p&gt;This issue can be mitigated by manually setting the `java.io.tmpdir` system property when launching the JVM.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;Jersey 2.34 and 3.0.2 forward sets the correct permissions on the temporary file created by Jersey.&lt;/p&gt;
&lt;p&gt;### References
 
 - https://github.com/eclipse-ee4j/jersey/pull/4712
 - [CWE-378: Creation of Temporary File With Insecure Permissions](https://cwe.mitre.org/data/definitions/378.html)
 - [CWE-379: Creation of Temporary File in Directory with Insecure Permissions](https://cwe.mitre.org/data/definitions/379.html)&lt;/p&gt;
&lt;p&gt;## Similar Vulnerabilities&lt;/p&gt;
&lt;p&gt;Similar, but not the same:&lt;/p&gt;
&lt;p&gt;- JUnit 4 - https://github.com/junit-team/junit4/security/advisories/GHSA-269g-pwp5-87pp
 - Google Guava - https://github.com/google/guava/issues/4011
 - Apache Ant - https://nvd.nist.gov/vuln/detail/CVE-2020-1945
 - JetBrains Kotlin Compiler - https://nvd.nist.gov/vuln/detail/CVE-2020-15824
 - Eclipse Jetty - https://github.com/eclipse/jetty.project/security/advisories/GHSA-g3wg-6mcf-8jj6&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;Original Disclosure:&lt;/p&gt;
&lt;p&gt;&amp;gt; Hello…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c43q-5hpj-4crv</guid>
    </item>
    <item>
      <title>gsd-2021-28168</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-28168</link>
      <description>gsd-2021-28168</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-28168</guid>
    </item>
    <item>
      <title>OESA-2021-1181 — jersey security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1181</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: jersey&lt;/p&gt;
&lt;p&gt;Jersey is the open source JAX-RS (JSR 311) production quality Reference Implementation for building RESTful Web services.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.(CVE-2021-28168)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: jersey&lt;/p&gt;
&lt;p&gt;Jersey is the open source JAX-RS (JSR 311) production quality Reference Implementation for building RESTful Web services.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.(CVE-2021-28168)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1181</guid>
    </item>
    <item>
      <title>RHSA-2021:3225 — Red Hat Security Advisory: Red Hat AMQ Streams 1.8.0 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3225</link>
      <description>&lt;p&gt;snakeyaml: Billion laughs attack via alias feature netty: Information disclosure via the local system temporary directory netty: possible request smuggling in HTTP/2 due missing validation netty: Request smuggling via content-length header json-smart: uncaught exception may lead to crash or information disclosure jetty: Symlink directory exposes webapp directory contents jetty: Ambiguous paths can access WEB-INF jetty: Resource exhaustion when receiving an invalid large TLS frame jersey: Local information disclosure via system temporary directory jetty: requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directory apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6 jetty: SessionListener can prevent a session from being invalidated breaking logout&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;snakeyaml: Billion laughs attack via alias feature netty: Information disclosure via the local system temporary directory netty: possible request smuggling in HTTP/2 due missing validation netty: Request smuggling via content-length header json-smart: uncaught exception may lead to crash or information disclosure jetty: Symlink directory exposes webapp directory contents jetty: Ambiguous paths can access WEB-INF jetty: Resource exhaustion when receiving an invalid large TLS frame jersey: Local information disclosure via system temporary directory jetty: requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directory apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6 jetty: SessionListener can prevent a session from being invalidated breaking logout&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3225</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1807 — Oracle Fusion Middleware: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1807</link>
      <description>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1807</guid>
    </item>
  </channel>
</rss>
