<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:45:55 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2023-42445</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-42445</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: gradle, Alpaquita:stream: gradle&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: gradle, Alpaquita:stream: gradle&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-42445</guid>
    </item>
    <item>
      <title>BIT-gradle-2023-42445 — Possible local file exfiltration by XML External entity injection</title>
      <link>https://cve.radiocsirt.org/vuln/bit-gradle-2023-42445</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gradle&lt;/p&gt;
&lt;p&gt;Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), just parsing XML can lead to exfiltration of local text files to a remote server. Gradle parses XML files for several purposes. Most of the time, Gradle parses XML files it generated or were already present locally. Only Ivy XML descriptors and Maven POM files can be fetched from remote repositories and parsed by Gradle. In Gradle 7.6.3 and 8.4, resolving XML external entities has been disabled for all use cases to protect against this vulnerability. Gradle will now refuse to parse XML files that have XML external entities.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gradle&lt;/p&gt;
&lt;p&gt;Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), just parsing XML can lead to exfiltration of local text files to a remote server. Gradle parses XML files for several purposes. Most of the time, Gradle parses XML files it generated or were already present locally. Only Ivy XML descriptors and Maven POM files can be fetched from remote repositories and parsed by Gradle. In Gradle 7.6.3 and 8.4, resolving XML external entities has been disabled for all use cases to protect against this vulnerability. Gradle will now refuse to parse XML files that have XML external entities.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-gradle-2023-42445</guid>
    </item>
    <item>
      <title>EUVD-2026-244348</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-244348</link>
      <description>EUVD-2026-244348</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-244348</guid>
    </item>
    <item>
      <title>fkie_cve-2023-42445</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-42445</link>
      <description>&lt;p&gt;Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), just parsing XML can lead to exfiltration of local text files to a remote server. Gradle parses XML files for several purposes. Most of the time, Gradle parses XML files it generated or were already present locally. Only Ivy XML descriptors and Maven POM files can be fetched from remote repositories and parsed by Gradle. In Gradle 7.6.3 and 8.4, resolving XML external entities has been disabled for all use cases to protect against this vulnerability. Gradle will now refuse to parse XML files that have XML external entities.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), just parsing XML can lead to exfiltration of local text files to a remote server. Gradle parses XML files for several purposes. Most of the time, Gradle parses XML files it generated or were already present locally. Only Ivy XML descriptors and Maven POM files can be fetched from remote repositories and parsed by Gradle. In Gradle 7.6.3 and 8.4, resolving XML external entities has been disabled for all use cases to protect against this vulnerability. Gradle will now refuse to parse XML files that have XML external entities.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-42445</guid>
    </item>
    <item>
      <title>gsd-2023-42445</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-42445</link>
      <description>gsd-2023-42445</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-42445</guid>
    </item>
    <item>
      <title>RHSA-2023:7678 — Red Hat Security Advisory: Red Hat AMQ Streams 2.6.0 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:7678</link>
      <description>&lt;p&gt;apache-ivy: XML External Entity vulnerability guava: insecure temporary directory creation JSON-java: parser confusion leads to OOM spring-boot: Security Bypass With Wildcard Pattern Matching on Cloud Foundry jose4j: Insecure iteration count setting bouncycastle: potential  blind LDAP injection attack using a self-signed certificate jetty: Improper validation of HTTP/1 content-length tomcat: Open Redirect vulnerability in FORM authentication gradle: Possible local text file exfiltration by XML External entity injection gradle: Incorrect permission assignment for symlinked files used in copy or archiving operations zookeeper: Authorization Bypass in Apache ZooKeeper&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache-ivy: XML External Entity vulnerability guava: insecure temporary directory creation JSON-java: parser confusion leads to OOM spring-boot: Security Bypass With Wildcard Pattern Matching on Cloud Foundry jose4j: Insecure iteration count setting bouncycastle: potential  blind LDAP injection attack using a self-signed certificate jetty: Improper validation of HTTP/1 content-length tomcat: Open Redirect vulnerability in FORM authentication gradle: Possible local text file exfiltration by XML External entity injection gradle: Incorrect permission assignment for symlinked files used in copy or archiving operations zookeeper: Authorization Bypass in Apache ZooKeeper&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:7678</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-42445</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-42445</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: gradle, Ubuntu:Pro:18.04:LTS: gradle, Ubuntu:20.04:LTS: gradle, Ubuntu:22.04:LTS: gradle, Ubuntu:24.04:LTS: gradle, Ubuntu:25.10: gradle, Ubuntu:26.04:LTS: gradle&lt;/p&gt;
&lt;p&gt;Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), just parsing XML can lead to exfiltration of local text files to a remote server. Gradle parses XML files for several purposes. Most of the time, Gradle parses XML files it generated or were already present locally. Only Ivy XML descriptors and Maven POM files can be fetched from remote repositories and parsed by Gradle. In Gradle 7.6.3 and 8.4, resolving XML external entities has been disabled for all use cases to protect against this vulnerability. Gradle will now refuse to parse XML files that have XML external entities.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: gradle, Ubuntu:Pro:18.04:LTS: gradle, Ubuntu:20.04:LTS: gradle, Ubuntu:22.04:LTS: gradle, Ubuntu:24.04:LTS: gradle, Ubuntu:25.10: gradle, Ubuntu:26.04:LTS: gradle&lt;/p&gt;
&lt;p&gt;Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), just parsing XML can lead to exfiltration of local text files to a remote server. Gradle parses XML files for several purposes. Most of the time, Gradle parses XML files it generated or were already present locally. Only Ivy XML descriptors and Maven POM files can be fetched from remote repositories and parsed by Gradle. In Gradle 7.6.3 and 8.4, resolving XML external entities has been disabled for all use cases to protect against this vulnerability. Gradle will now refuse to parse XML files that have XML external entities.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-42445</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-3070 — Red Hat JBoss A-MQ: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3070</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss A-MQ ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen, Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss A-MQ ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen, Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3070</guid>
    </item>
  </channel>
</rss>
