<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 02:14:00 +0000</lastBuildDate>
    <item>
      <title>BIT-solr-2021-33813</title>
      <link>https://cve.radiocsirt.org/vuln/bit-solr-2021-33813</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: solr&lt;/p&gt;
&lt;p&gt;An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: solr&lt;/p&gt;
&lt;p&gt;An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-solr-2021-33813</guid>
    </item>
    <item>
      <title>certfr-2022-avi-386 — De multiples vulnérabilités ont été découvertes dans IBM QRadar SIEM.
Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-386</link>
      <description>certfr-2022-avi-386</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-386</guid>
    </item>
    <item>
      <title>EUVD-2026-28598</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-28598</link>
      <description>EUVD-2026-28598</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-28598</guid>
    </item>
    <item>
      <title>fkie_cve-2021-33813</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-33813</link>
      <description>&lt;p&gt;An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-33813</guid>
    </item>
    <item>
      <title>GHSA-2363-cqg2-863c — XML External Entity (XXE) Injection in JDOM</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2363-cqg2-863c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jdom:jdom2, Maven: org.jdom:jdom&lt;/p&gt;
&lt;p&gt;An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. As a workaround, to avoid external entities being expanded, one can call `builder.setExpandEntities(false)` and they won&amp;#39;t be expanded.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jdom:jdom2, Maven: org.jdom:jdom&lt;/p&gt;
&lt;p&gt;An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. As a workaround, to avoid external entities being expanded, one can call `builder.setExpandEntities(false)` and they won&amp;#39;t be expanded.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2363-cqg2-863c</guid>
    </item>
    <item>
      <title>gsd-2021-33813</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-33813</link>
      <description>gsd-2021-33813</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-33813</guid>
    </item>
    <item>
      <title>OESA-2022-1630 — jdom2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1630</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: jdom2, openEuler:20.03-LTS-SP3: jdom2, openEuler:22.03-LTS: jdom2&lt;/p&gt;
&lt;p&gt;JDOM is an in-memory representation of an XML document. XML consists of elements (which have attributes), text data, &amp;#39;entity&amp;#39; references, processing instructions, and comments. XML documents can also have a DocType declaration, Comments, and Processing Instructions before the root element.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.(CVE-2021-33813)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: jdom2, openEuler:20.03-LTS-SP3: jdom2, openEuler:22.03-LTS: jdom2&lt;/p&gt;
&lt;p&gt;JDOM is an in-memory representation of an XML document. XML consists of elements (which have attributes), text data, &amp;#39;entity&amp;#39; references, processing instructions, and comments. XML documents can also have a DocType declaration, Comments, and Processing Instructions before the root element.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.(CVE-2021-33813)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1630</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:1031-1 — Security update for jdom2</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1031-1</link>
      <description>&lt;p&gt;Security update for jdom2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for jdom2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:1031-1</guid>
    </item>
    <item>
      <title>RHSA-2022:1029 — Red Hat Security Advisory: Red Hat Integration Camel-K 1.6.4 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:1029</link>
      <description>&lt;p&gt;guava: local information disclosure via temporary directory created with unsafe permissions bouncycastle: Timing issue within the EC math library jetty: buffer not correctly recycled in Gzip Request inflation undertow: buffer leak on incoming websocket PONG message may lead to DoS RESTEasy: PathParam in RESTEasy can lead to a reflected XSS attack XStream: SSRF can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host maven: Block repositories using http by default jersey: Local information disclosure via system temporary directory jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate jdom: XXE allows attackers to cause a DoS via a crafted HTTP request cyrus-sasl: failure to properly escape SQL input allows an attacker to execute arbitrary SQL commands&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;guava: local information disclosure via temporary directory created with unsafe permissions bouncycastle: Timing issue within the EC math library jetty: buffer not correctly recycled in Gzip Request inflation undertow: buffer leak on incoming websocket PONG message may lead to DoS RESTEasy: PathParam in RESTEasy can lead to a reflected XSS attack XStream: SSRF can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host maven: Block repositories using http by default jersey: Local information disclosure via system temporary directory jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate jdom: XXE allows attackers to cause a DoS via a crafted HTTP request cyrus-sasl: failure to properly escape SQL input allows an attacker to execute arbitrary SQL commands&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:1029</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:2293-1 — Security update for jdom2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:2293-1</link>
      <description>&lt;p&gt;Security update for jdom2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for jdom2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:2293-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-33813</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-33813</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: libjdom1-java, Ubuntu:16.04:LTS: libjdom1-java, Ubuntu:16.04:LTS: libjdom2-java, Ubuntu:18.04:LTS: libjdom1-java, Ubuntu:18.04:LTS: libjdom2-java, Ubuntu:20.04:LTS: libjdom1-java, Ubuntu:20.04:LTS: libjdom2-java, Ubuntu:22.04:LTS: libjdom1-java, Ubuntu:22.04:LTS: libjdom2-java, Ubuntu:24.04:LTS: libjdom1-java and 5 more&lt;/p&gt;
&lt;p&gt;An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: libjdom1-java, Ubuntu:16.04:LTS: libjdom1-java, Ubuntu:16.04:LTS: libjdom2-java, Ubuntu:18.04:LTS: libjdom1-java, Ubuntu:18.04:LTS: libjdom2-java, Ubuntu:20.04:LTS: libjdom1-java, Ubuntu:20.04:LTS: libjdom2-java, Ubuntu:22.04:LTS: libjdom1-java, Ubuntu:22.04:LTS: libjdom2-java, Ubuntu:24.04:LTS: libjdom1-java and 5 more&lt;/p&gt;
&lt;p&gt;An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-33813</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0607 — Red Hat FUSE: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</guid>
    </item>
  </channel>
</rss>
