<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:54:27 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:9058 — Important: prometheus-jmx-exporter security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:9058</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: prometheus-jmx-exporter, AlmaLinux:8: prometheus-jmx-exporter-openjdk11, AlmaLinux:8: prometheus-jmx-exporter-openjdk17, AlmaLinux:8: prometheus-jmx-exporter-openjdk8&lt;/p&gt;
&lt;p&gt;Prometheus JMX Exporter is a JMX to Prometheus exporter: a collector that can be configured to scrape and expose MBeans of a JMX target.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* SnakeYaml: Constructor Deserialization Remote Code Execution (CVE-2022-1471)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: prometheus-jmx-exporter, AlmaLinux:8: prometheus-jmx-exporter-openjdk11, AlmaLinux:8: prometheus-jmx-exporter-openjdk17, AlmaLinux:8: prometheus-jmx-exporter-openjdk8&lt;/p&gt;
&lt;p&gt;Prometheus JMX Exporter is a JMX to Prometheus exporter: a collector that can be configured to scrape and expose MBeans of a JMX target.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* SnakeYaml: Constructor Deserialization Remote Code Execution (CVE-2022-1471)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:9058</guid>
    </item>
    <item>
      <title>bdu:2023-00013</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-00013</link>
      <description>bdu:2023-00013</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-00013</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0287 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à u…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0287</link>
      <description>certfr-2023-avi-0287</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0287</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CI66802 — Security fixes for CVE-2015-2104, CVE-2020-8908, CVE-2021-21295, CVE-2021-21409, CVE-2021-37136, CVE-2022-1471, CVE-202…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</guid>
    </item>
    <item>
      <title>EUVD-2026-245037</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-245037</link>
      <description>EUVD-2026-245037</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-245037</guid>
    </item>
    <item>
      <title>fkie_cve-2022-1471</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-1471</link>
      <description>&lt;p&gt;SnakeYaml&amp;#39;s Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml&amp;#39;s SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SnakeYaml&amp;#39;s Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml&amp;#39;s SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-1471</guid>
    </item>
    <item>
      <title>GHSA-mjmj-j48q-9wg2 — SnakeYaml Constructor Deserialization Remote Code Execution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mjmj-j48q-9wg2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.yaml:snakeyaml&lt;/p&gt;
&lt;p&gt;### Summary
SnakeYaml&amp;#39;s `Constructor` class, which inherits from `SafeConstructor`, allows
any type be deserialized given the following line:&lt;/p&gt;
&lt;p&gt;new Yaml(new Constructor(TestDataClass.class)).load(yamlContent);&lt;/p&gt;
&lt;p&gt;Types do not have to match the types of properties in the
target class. A `ConstructorException` is thrown, but only after a malicious
payload is deserialized.&lt;/p&gt;
&lt;p&gt;### Severity
High, lack of type checks during deserialization allows remote code execution.&lt;/p&gt;
&lt;p&gt;### Proof of Concept
Execute `bash run.sh`. The PoC uses Constructor to deserialize a payload
for RCE. RCE is demonstrated by using a payload which performs a http request to
http://127.0.0.1:8000.&lt;/p&gt;
&lt;p&gt;Example output of successful run of proof of concept:&lt;/p&gt;
&lt;p&gt;```
$ bash run.sh&lt;/p&gt;
&lt;p&gt;[+] Downloading snakeyaml if needed
[+] Starting mock HTTP server on 127.0.0.1:8000 to demonstrate RCE
nc: no process found
[+] Compiling and running Proof of Concept, which a payload that sends a HTTP request to mock web server.
[+] An exception is expected.
Exception:
Cannot create property=payload for JavaBean=Main$TestDataClass@3cbbc1e0
 in &amp;#39;string&amp;#39;, line 1, column 1:
    payload: !!javax.script.ScriptEn ... 
    ^
Can not set java.lang.String field Main$TestDataClass.payload to javax.script.ScriptEngineManager
 in &amp;#39;string&amp;#39;, line 1, column 10:
    payload: !!javax.script.ScriptEngineManag ... 
             ^&lt;/p&gt;
&lt;p&gt;at org.yaml.snakeyaml.constructor.Constructor$ConstructMapping.constructJavaBean2ndStep(Constructor.java:291)
	at org.yaml.snakeyaml.constru…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.yaml:snakeyaml&lt;/p&gt;
&lt;p&gt;### Summary
SnakeYaml&amp;#39;s `Constructor` class, which inherits from `SafeConstructor`, allows
any type be deserialized given the following line:&lt;/p&gt;
&lt;p&gt;new Yaml(new Constructor(TestDataClass.class)).load(yamlContent);&lt;/p&gt;
&lt;p&gt;Types do not have to match the types of properties in the
target class. A `ConstructorException` is thrown, but only after a malicious
payload is deserialized.&lt;/p&gt;
&lt;p&gt;### Severity
High, lack of type checks during deserialization allows remote code execution.&lt;/p&gt;
&lt;p&gt;### Proof of Concept
Execute `bash run.sh`. The PoC uses Constructor to deserialize a payload
for RCE. RCE is demonstrated by using a payload which performs a http request to
http://127.0.0.1:8000.&lt;/p&gt;
&lt;p&gt;Example output of successful run of proof of concept:&lt;/p&gt;
&lt;p&gt;```
$ bash run.sh&lt;/p&gt;
&lt;p&gt;[+] Downloading snakeyaml if needed
[+] Starting mock HTTP server on 127.0.0.1:8000 to demonstrate RCE
nc: no process found
[+] Compiling and running Proof of Concept, which a payload that sends a HTTP request to mock web server.
[+] An exception is expected.
Exception:
Cannot create property=payload for JavaBean=Main$TestDataClass@3cbbc1e0
 in &amp;#39;string&amp;#39;, line 1, column 1:
    payload: !!javax.script.ScriptEn ... 
    ^
Can not set java.lang.String field Main$TestDataClass.payload to javax.script.ScriptEngineManager
 in &amp;#39;string&amp;#39;, line 1, column 10:
    payload: !!javax.script.ScriptEngineManag ... 
             ^&lt;/p&gt;
&lt;p&gt;at org.yaml.snakeyaml.constructor.Constructor$ConstructMapping.constructJavaBean2ndStep(Constructor.java:291)
	at org.yaml.snakeyaml.constru…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mjmj-j48q-9wg2</guid>
    </item>
    <item>
      <title>gsd-2022-1471</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-1471</link>
      <description>gsd-2022-1471</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-1471</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13151-1 — jackson-dataformat-csv-2.15.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13151-1</link>
      <description>&lt;p&gt;jackson-dataformat-csv-2.15.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jackson-dataformat-csv-2.15.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13151-1</guid>
    </item>
    <item>
      <title>RHBA-2023:0030 — Red Hat Bug Fix Advisory: updated RHEL-8 based Middleware Containers container images</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2023:0030</link>
      <description>&lt;p&gt;SnakeYaml: Constructor Deserialization Remote Code Execution&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SnakeYaml: Constructor Deserialization Remote Code Execution&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2023:0030</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-1471</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-1471</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: snakeyaml, Ubuntu:Pro:16.04:LTS: snakeyaml, Ubuntu:Pro:18.04:LTS: snakeyaml, Ubuntu:Pro:20.04:LTS: snakeyaml, Ubuntu:22.04:LTS: snakeyaml, Ubuntu:24.04:LTS: snakeyaml&lt;/p&gt;
&lt;p&gt;SnakeYaml&amp;#39;s Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml&amp;#39;s SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: snakeyaml, Ubuntu:Pro:16.04:LTS: snakeyaml, Ubuntu:Pro:18.04:LTS: snakeyaml, Ubuntu:Pro:20.04:LTS: snakeyaml, Ubuntu:22.04:LTS: snakeyaml, Ubuntu:24.04:LTS: snakeyaml&lt;/p&gt;
&lt;p&gt;SnakeYaml&amp;#39;s Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml&amp;#39;s SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-1471</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2347 — Red Hat Enterprise Linux: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2347</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux und Oracle Linux ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux und Oracle Linux ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2347</guid>
    </item>
  </channel>
</rss>
