<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:06:27 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-01786</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-01786</link>
      <description>bdu:2024-01786</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-01786</guid>
    </item>
    <item>
      <title>BIT-vault-2023-0620 — Vault Vulnerable to SQL Injection When Configuring the Microsoft SQL Database Storage Backend</title>
      <link>https://cve.radiocsirt.org/vuln/bit-vault-2023-0620</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: vault&lt;/p&gt;
&lt;p&gt;HashiCorp Vault and Vault Enterprise versions 0.8.0 through 1.13.1 are vulnerable to an SQL injection attack when configuring the Microsoft SQL (MSSQL) Database Storage Backend. When configuring the MSSQL plugin through the local, certain parameters are not sanitized when passed to the user-provided MSSQL database. An attacker may modify these parameters to execute a malicious SQL command.&lt;/p&gt;
&lt;p&gt;This issue is fixed in versions 1.13.1, 1.12.5, and 1.11.9.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: vault&lt;/p&gt;
&lt;p&gt;HashiCorp Vault and Vault Enterprise versions 0.8.0 through 1.13.1 are vulnerable to an SQL injection attack when configuring the Microsoft SQL (MSSQL) Database Storage Backend. When configuring the MSSQL plugin through the local, certain parameters are not sanitized when passed to the user-provided MSSQL database. An attacker may modify these parameters to execute a malicious SQL command.&lt;/p&gt;
&lt;p&gt;This issue is fixed in versions 1.13.1, 1.12.5, and 1.11.9.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-vault-2023-0620</guid>
    </item>
    <item>
      <title>EUVD-2026-216133</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-216133</link>
      <description>EUVD-2026-216133</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-216133</guid>
    </item>
    <item>
      <title>fkie_cve-2023-0620</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-0620</link>
      <description>&lt;p&gt;HashiCorp Vault and Vault Enterprise versions 0.8.0 through 1.13.1 are vulnerable to an SQL injection attack when configuring the Microsoft SQL (MSSQL) Database Storage Backend. When configuring the MSSQL plugin through the local, certain parameters are not sanitized when passed to the user-provided MSSQL database. An attacker may modify these parameters to execute a malicious SQL command.&lt;/p&gt;
&lt;p&gt;This issue is fixed in versions 1.13.1, 1.12.5, and 1.11.9.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;HashiCorp Vault and Vault Enterprise versions 0.8.0 through 1.13.1 are vulnerable to an SQL injection attack when configuring the Microsoft SQL (MSSQL) Database Storage Backend. When configuring the MSSQL plugin through the local, certain parameters are not sanitized when passed to the user-provided MSSQL database. An attacker may modify these parameters to execute a malicious SQL command.&lt;/p&gt;
&lt;p&gt;This issue is fixed in versions 1.13.1, 1.12.5, and 1.11.9.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-0620</guid>
    </item>
    <item>
      <title>GHSA-v3hp-mcj5-pg39 — HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v3hp-mcj5-pg39</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/hashicorp/vault&lt;/p&gt;
&lt;p&gt;HashiCorp Vault and Vault Enterprise versions 0.8.0 until 1.13.1 are vulnerable to an SQL injection attack when using the Microsoft SQL (MSSQL) Database Storage Backend. When configuring the MSSQL plugin, certain parameters are required to establish a connection (schema, database, and table) are not sanitized when passed to the user-provided MSSQL database. A privileged attacker with the ability to write arbitrary data to Vault&amp;#39;s configuration may modify these parameters to execute a malicious SQL command when the Vault configuration is applied. This issue is fixed in versions 1.13.1, 1.12.5, and 1.11.9.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/hashicorp/vault&lt;/p&gt;
&lt;p&gt;HashiCorp Vault and Vault Enterprise versions 0.8.0 until 1.13.1 are vulnerable to an SQL injection attack when using the Microsoft SQL (MSSQL) Database Storage Backend. When configuring the MSSQL plugin, certain parameters are required to establish a connection (schema, database, and table) are not sanitized when passed to the user-provided MSSQL database. A privileged attacker with the ability to write arbitrary data to Vault&amp;#39;s configuration may modify these parameters to execute a malicious SQL command when the Vault configuration is applied. This issue is fixed in versions 1.13.1, 1.12.5, and 1.11.9.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v3hp-mcj5-pg39</guid>
    </item>
    <item>
      <title>gsd-2023-0620</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-0620</link>
      <description>gsd-2023-0620</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-0620</guid>
    </item>
    <item>
      <title>RHSA-2023:1326 — Red Hat Security Advisory: OpenShift Container Platform 4.13.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:1326</link>
      <description>&lt;p&gt;go-yaml: Denial of Service in go-yaml goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be mongo-go-driver: specific cstrings input may not be properly validated golang: out-of-bounds read in golang.org/x/text/language leads to DoS prometheus/client_golang: Denial of service using InstrumentHandlerCounter helm: Denial of service through through repository index file helm: Denial of service through schema file golang: crash in a golang.org/x/crypto/ssh server vault: insufficient certificate revocation list checking golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests x/net/http2/h2c: request smuggling golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding golang: crypto/tls: large handshake records may cause panics golang: net/http, mime/multipart: denial of service from excessive resource consumption exporter-toolkit: authentication bypass via cache poisoning vault: Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File hashicorp/vault: Vault’s PKI Issuer Endpoint Did Not Correctly Authorize Access to Issuer Metadata hashicorp/vault: Cache-Timing Attacks During Seal and Unseal Operations helm: getHostByName Function Information Disclosure containerd: Supplementary groups are not set up properly runc: Rootless runc makes `/sys/fs/cgroup` writable runc: volume mount race condition (regression of CVE-2019-19921) runc: AppArmor can be bypassed when `/pro…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go-yaml: Denial of Service in go-yaml goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be mongo-go-driver: specific cstrings input may not be properly validated golang: out-of-bounds read in golang.org/x/text/language leads to DoS prometheus/client_golang: Denial of service using InstrumentHandlerCounter helm: Denial of service through through repository index file helm: Denial of service through schema file golang: crash in a golang.org/x/crypto/ssh server vault: insufficient certificate revocation list checking golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests x/net/http2/h2c: request smuggling golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding golang: crypto/tls: large handshake records may cause panics golang: net/http, mime/multipart: denial of service from excessive resource consumption exporter-toolkit: authentication bypass via cache poisoning vault: Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File hashicorp/vault: Vault’s PKI Issuer Endpoint Did Not Correctly Authorize Access to Issuer Metadata hashicorp/vault: Cache-Timing Attacks During Seal and Unseal Operations helm: getHostByName Function Information Disclosure containerd: Supplementary groups are not set up properly runc: Rootless runc makes `/sys/fs/cgroup` writable runc: volume mount race condition (regression of CVE-2019-19921) runc: AppArmor can be bypassed when `/pro…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:1326</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0795 — Hashicorp Vault: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0795</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Hashicorp Vault ausnutzen, um Dateien zu manipulieren, einen Denial of Service Zustand herbeizuführen oder die Kryptographie zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Hashicorp Vault ausnutzen, um Dateien zu manipulieren, einen Denial of Service Zustand herbeizuführen oder die Kryptographie zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0795</guid>
    </item>
  </channel>
</rss>
