<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:31:16 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-06049</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-06049</link>
      <description>bdu:2023-06049</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-06049</guid>
    </item>
    <item>
      <title>EUVD-2026-187447</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-187447</link>
      <description>EUVD-2026-187447</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-187447</guid>
    </item>
    <item>
      <title>fkie_cve-2022-3874</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-3874</link>
      <description>&lt;p&gt;A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora CoreOS configurations in templates, possibly resulting in arbitrary command execution on the underlying operating system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora CoreOS configurations in templates, possibly resulting in arbitrary command execution on the underlying operating system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-3874</guid>
    </item>
    <item>
      <title>Withdrawn: GHSA-9jfq-54vc-9rr2 — Foreman Transpilation Enables OS Command Injection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9jfq-54vc-9rr2</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: foreman&lt;/p&gt;
&lt;p&gt;A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora CoreOS configurations in templates, possibly resulting in arbitrary command execution on the underlying operating system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: foreman&lt;/p&gt;
&lt;p&gt;A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora CoreOS configurations in templates, possibly resulting in arbitrary command execution on the underlying operating system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9jfq-54vc-9rr2</guid>
    </item>
    <item>
      <title>gsd-2022-3874</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-3874</link>
      <description>gsd-2022-3874</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-3874</guid>
    </item>
    <item>
      <title>RHSA-2023:5931 — Red Hat Security Advisory: Satellite 6.13.5 Async Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:5931</link>
      <description>&lt;p&gt;openssl: c_rehash script allows command injection openssl: the c_rehash script allows command injection foreman: OS command injection via ct_command and fcct_command GitPython: improper user input validation leads into a RCE ruby-git: code injection vulnerability ruby-git: code injection vulnerability Satellite/Foreman: Arbitrary code execution through yaml global parameters OpenSSL: Excessive time spent checking DH q parameter value python-django: Potential bypass of validation when uploading multiple files using one form field python-django: Potential regular expression denial of service vulnerability in EmailValidator/URLValidator golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) GitPython: Insecure non-multi options in clone and clone_from is not blocked HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssl: c_rehash script allows command injection openssl: the c_rehash script allows command injection foreman: OS command injection via ct_command and fcct_command GitPython: improper user input validation leads into a RCE ruby-git: code injection vulnerability ruby-git: code injection vulnerability Satellite/Foreman: Arbitrary code execution through yaml global parameters OpenSSL: Excessive time spent checking DH q parameter value python-django: Potential bypass of validation when uploading multiple files using one form field python-django: Potential regular expression denial of service vulnerability in EmailValidator/URLValidator golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) GitPython: Insecure non-multi options in clone and clone_from is not blocked HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:5931</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2723 — Red Hat Satellite: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2723</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Red Hat Satellite ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Red Hat Satellite ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2723</guid>
    </item>
  </channel>
</rss>
