<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:02:11 +0000</lastBuildDate>
    <item>
      <title>certfr-2023-avi-0063 — Une vulnérabilité a été découverte dans Grafana. Elle permet à un
attaquant de provoquer une élévation de privilèges.</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0063</link>
      <description>certfr-2023-avi-0063</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0063</guid>
    </item>
    <item>
      <title>EUVD-2026-233386</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-233386</link>
      <description>EUVD-2026-233386</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-233386</guid>
    </item>
    <item>
      <title>fkie_cve-2022-41912</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-41912</link>
      <description>&lt;p&gt;The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-41912</guid>
    </item>
    <item>
      <title>GHSA-j2jp-wvqg-wc2g — crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j2jp-wvqg-wc2g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/crewjam/saml&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This issue has been corrected in version 0.4.9.&lt;/p&gt;
&lt;p&gt;### Credit&lt;/p&gt;
&lt;p&gt;This issue was reported by Felix Wilhelm from Google Project Zero.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/crewjam/saml&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This issue has been corrected in version 0.4.9.&lt;/p&gt;
&lt;p&gt;### Credit&lt;/p&gt;
&lt;p&gt;This issue was reported by Felix Wilhelm from Google Project Zero.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j2jp-wvqg-wc2g</guid>
    </item>
    <item>
      <title>gsd-2022-41912</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-41912</link>
      <description>gsd-2022-41912</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-41912</guid>
    </item>
    <item>
      <title>RHSA-2022:9040 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.6.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:9040</link>
      <description>&lt;p&gt;nodejs-minimatch: ReDoS via the braceExpand function crewjam/saml: Authentication bypass when processing SAML responses containing multiple Assertion elements&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-minimatch: ReDoS via the braceExpand function crewjam/saml: Authentication bypass when processing SAML responses containing multiple Assertion elements&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:9040</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-41912</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41912</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-github-crewjam-saml&lt;/p&gt;
&lt;p&gt;The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-github-crewjam-saml&lt;/p&gt;
&lt;p&gt;The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41912</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2338 — Red Hat Enterprise Linux (Advanced Cluster Management): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2338</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux Advanced Cluster Management ausnutzen, um einen Denial of Service Angriff durchzuführen oder die Authentisierung zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux Advanced Cluster Management ausnutzen, um einen Denial of Service Angriff durchzuführen oder die Authentisierung zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2338</guid>
    </item>
  </channel>
</rss>
