<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:05:19 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-04278</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-04278</link>
      <description>bdu:2022-04278</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-04278</guid>
    </item>
    <item>
      <title>certfr-2022-avi-1059 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1059</link>
      <description>certfr-2022-avi-1059</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-1059</guid>
    </item>
    <item>
      <title>cnvd-2022-49973</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-49973</link>
      <description>cnvd-2022-49973</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-49973</guid>
    </item>
    <item>
      <title>EUVD-2026-17740</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-17740</link>
      <description>EUVD-2026-17740</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-17740</guid>
    </item>
    <item>
      <title>fkie_cve-2022-33980</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-33980</link>
      <description>&lt;p&gt;Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is &amp;#34;${prefix:name}&amp;#34;, where &amp;#34;prefix&amp;#34; is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - &amp;#34;script&amp;#34; - execute expressions using the JVM script execution engine (javax.script) - &amp;#34;dns&amp;#34; - resolve dns records - &amp;#34;url&amp;#34; - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Configuration 2.8.0, which disables the problematic interpolators by default.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is &amp;#34;${prefix:name}&amp;#34;, where &amp;#34;prefix&amp;#34; is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - &amp;#34;script&amp;#34; - execute expressions using the JVM script execution engine (javax.script) - &amp;#34;dns&amp;#34; - resolve dns records - &amp;#34;url&amp;#34; - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Configuration 2.8.0, which disables the problematic interpolators by default.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-33980</guid>
    </item>
    <item>
      <title>GHSA-xj57-8qj4-c4m6 — Code injection in Apache Commons Configuration</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xj57-8qj4-c4m6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.commons:commons-configuration2&lt;/p&gt;
&lt;p&gt;Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is &amp;#34;${prefix:name}&amp;#34;, where &amp;#34;prefix&amp;#34; is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - &amp;#34;script&amp;#34; - execute expressions using the JVM script execution engine (javax.script) - &amp;#34;dns&amp;#34; - resolve dns records - &amp;#34;url&amp;#34; - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Configuration 2.8.0, which disables the problematic interpolators by default.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.commons:commons-configuration2&lt;/p&gt;
&lt;p&gt;Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is &amp;#34;${prefix:name}&amp;#34;, where &amp;#34;prefix&amp;#34; is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - &amp;#34;script&amp;#34; - execute expressions using the JVM script execution engine (javax.script) - &amp;#34;dns&amp;#34; - resolve dns records - &amp;#34;url&amp;#34; - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Configuration 2.8.0, which disables the problematic interpolators by default.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xj57-8qj4-c4m6</guid>
    </item>
    <item>
      <title>gsd-2022-33980</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-33980</link>
      <description>gsd-2022-33980</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-33980</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13259-1 — apache-commons-configuration2-2.9.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13259-1</link>
      <description>&lt;p&gt;apache-commons-configuration2-2.9.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache-commons-configuration2-2.9.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13259-1</guid>
    </item>
    <item>
      <title>RHSA-2022:6916 — Red Hat Security Advisory: Red Hat AMQ Broker 7.10.1 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:6916</link>
      <description>&lt;p&gt;gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation netty: world readable temporary file containing sensitive data apache-commons-configuration: Apache Commons Configuration insecure interpolation defaults activemq-artemis: AMQ Broker web console HTML Injection&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation netty: world readable temporary file containing sensitive data apache-commons-configuration: Apache Commons Configuration insecure interpolation defaults activemq-artemis: AMQ Broker web console HTML Injection&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:6916</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-33980</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-33980</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: commons-configuration2, Ubuntu:20.04:LTS: commons-configuration2, Ubuntu:22.04:LTS: commons-configuration2&lt;/p&gt;
&lt;p&gt;Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is &amp;#34;${prefix:name}&amp;#34;, where &amp;#34;prefix&amp;#34; is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - &amp;#34;script&amp;#34; - execute expressions using the JVM script execution engine (javax.script) - &amp;#34;dns&amp;#34; - resolve dns records - &amp;#34;url&amp;#34; - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Configuration 2.8.0, which disables the problematic interpolators by default.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: commons-configuration2, Ubuntu:20.04:LTS: commons-configuration2, Ubuntu:22.04:LTS: commons-configuration2&lt;/p&gt;
&lt;p&gt;Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is &amp;#34;${prefix:name}&amp;#34;, where &amp;#34;prefix&amp;#34; is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - &amp;#34;script&amp;#34; - execute expressions using the JVM script execution engine (javax.script) - &amp;#34;dns&amp;#34; - resolve dns records - &amp;#34;url&amp;#34; - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Configuration 2.8.0, which disables the problematic interpolators by default.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-33980</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0590 — Apache Commons: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0590</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann eine Schwachstelle in Apache Commons ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann eine Schwachstelle in Apache Commons ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0590</guid>
    </item>
  </channel>
</rss>
