<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:36:13 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-21105</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-21105</link>
      <description>EUVD-2026-21105</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-21105</guid>
    </item>
    <item>
      <title>fkie_cve-2021-3763</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3763</link>
      <description>&lt;p&gt;A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access some limited information even when the role the user is assigned to should not be allow access to the management console. The main impact is to confidentiality as this flaw means some role bindings are incorrectly checked, some privileged meta information such as queue names and configuration details are disclosed but the impact is limited as not all information is accessible and there is no affect to integrity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access some limited information even when the role the user is assigned to should not be allow access to the management console. The main impact is to confidentiality as this flaw means some role bindings are incorrectly checked, some privileged meta information such as queue names and configuration details are disclosed but the impact is limited as not all information is accessible and there is no affect to integrity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-3763</guid>
    </item>
    <item>
      <title>GHSA-c78g-8qvx-mmh9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c78g-8qvx-mmh9</link>
      <description>&lt;p&gt;A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access some limited information even when the role the user is assigned to should not be allow access to the management console. The main impact is to confidentiality as this flaw means some role bindings are incorrectly checked, some privileged meta information such as queue names and configuration details are disclosed but the impact is limited as not all information is accessible and there is no affect to integrity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access some limited information even when the role the user is assigned to should not be allow access to the management console. The main impact is to confidentiality as this flaw means some role bindings are incorrectly checked, some privileged meta information such as queue names and configuration details are disclosed but the impact is limited as not all information is accessible and there is no affect to integrity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c78g-8qvx-mmh9</guid>
    </item>
    <item>
      <title>gsd-2021-3763</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-3763</link>
      <description>gsd-2021-3763</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-3763</guid>
    </item>
    <item>
      <title>RHSA-2021:3700 — Red Hat Security Advisory: Red Hat AMQ Broker 7.9.0 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3700</link>
      <description>&lt;p&gt;apache-httpclient: incorrect handling of malformed authority component in request URIs jetty: request containing multiple Accept headers with a large number of &amp;#34;quality&amp;#34; parameters may lead to DoS Broker: discloses JDBC username and password in the application log file 7: Incorrect privilege in Management Console resteasy: Error message exposes endpoint class information netty: Information disclosure via the local system temporary directory netty: possible request smuggling in HTTP/2 due missing validation netty: Request smuggling via content-length header jetty: Symlink directory exposes webapp directory contents jetty: Ambiguous paths can access WEB-INF jetty: Resource exhaustion when receiving an invalid large TLS frame jetty: requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directory apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6 jetty: SessionListener can prevent a session from being invalidated breaking logout jetty: crafted URIs allow bypassing security constraints&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache-httpclient: incorrect handling of malformed authority component in request URIs jetty: request containing multiple Accept headers with a large number of &amp;#34;quality&amp;#34; parameters may lead to DoS Broker: discloses JDBC username and password in the application log file 7: Incorrect privilege in Management Console resteasy: Error message exposes endpoint class information netty: Information disclosure via the local system temporary directory netty: possible request smuggling in HTTP/2 due missing validation netty: Request smuggling via content-length header jetty: Symlink directory exposes webapp directory contents jetty: Ambiguous paths can access WEB-INF jetty: Resource exhaustion when receiving an invalid large TLS frame jetty: requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directory apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6 jetty: SessionListener can prevent a session from being invalidated breaking logout jetty: crafted URIs allow bypassing security constraints&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3700</guid>
    </item>
  </channel>
</rss>
