<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 14:28:16 +0000</lastBuildDate>
    <item>
      <title>BIT-minio-2022-35919 — Authenticated requests for server update admin API allows path traversal in minio</title>
      <link>https://cve.radiocsirt.org/vuln/bit-minio-2022-35919</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: minio&lt;/p&gt;
&lt;p&gt;MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions all &amp;#39;admin&amp;#39; users authorized for `admin:ServerUpdate` can selectively trigger an error that in response, returns the content of the path requested. Any normal OS system would allow access to contents at any arbitrary paths that are readable by MinIO process. Users are advised to upgrade. Users unable to upgrade may disable ServerUpdate API by denying the `admin:ServerUpdate` action for your admin users via IAM policies.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: minio&lt;/p&gt;
&lt;p&gt;MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions all &amp;#39;admin&amp;#39; users authorized for `admin:ServerUpdate` can selectively trigger an error that in response, returns the content of the path requested. Any normal OS system would allow access to contents at any arbitrary paths that are readable by MinIO process. Users are advised to upgrade. Users unable to upgrade may disable ServerUpdate API by denying the `admin:ServerUpdate` action for your admin users via IAM policies.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-minio-2022-35919</guid>
    </item>
    <item>
      <title>EUVD-2026-232666</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232666</link>
      <description>EUVD-2026-232666</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232666</guid>
    </item>
    <item>
      <title>fkie_cve-2022-35919</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-35919</link>
      <description>&lt;p&gt;MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions all &amp;#39;admin&amp;#39; users authorized for `admin:ServerUpdate` can selectively trigger an error that in response, returns the content of the path requested. Any normal OS system would allow access to contents at any arbitrary paths that are readable by MinIO process. Users are advised to upgrade. Users unable to upgrade may disable ServerUpdate API by denying the `admin:ServerUpdate` action for your admin users via IAM policies.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions all &amp;#39;admin&amp;#39; users authorized for `admin:ServerUpdate` can selectively trigger an error that in response, returns the content of the path requested. Any normal OS system would allow access to contents at any arbitrary paths that are readable by MinIO process. Users are advised to upgrade. Users unable to upgrade may disable ServerUpdate API by denying the `admin:ServerUpdate` action for your admin users via IAM policies.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-35919</guid>
    </item>
    <item>
      <title>gsd-2022-35919</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-35919</link>
      <description>gsd-2022-35919</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-35919</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1461 — IBM Spectrum Protect: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1461</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Spectrum Protect ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, einen Denial of Service Zustand herbeizuführen oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Spectrum Protect ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, einen Denial of Service Zustand herbeizuführen oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1461</guid>
    </item>
  </channel>
</rss>
