<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:52:42 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-06799</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-06799</link>
      <description>bdu:2023-06799</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-06799</guid>
    </item>
    <item>
      <title>BIT-zookeeper-2023-44981 — Apache ZooKeeper: Authorization bypass in SASL Quorum Peer Authentication</title>
      <link>https://cve.radiocsirt.org/vuln/bit-zookeeper-2023-44981</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: zookeeper&lt;/p&gt;
&lt;p&gt;Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if it&amp;#39;s missing, like &amp;#39;eve@EXAMPLE.COM&amp;#39;, the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. Quorum Peer authentication is not enabled by default.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 3.9.1, 3.8.3, 3.7.2, which fixes the issue.&lt;/p&gt;
&lt;p&gt;Alternately ensure the ensemble election/quorum communication is protected by a firewall as this will mitigate the issue.&lt;/p&gt;
&lt;p&gt;See the documentation for more details on correct cluster administration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: zookeeper&lt;/p&gt;
&lt;p&gt;Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if it&amp;#39;s missing, like &amp;#39;eve@EXAMPLE.COM&amp;#39;, the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. Quorum Peer authentication is not enabled by default.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 3.9.1, 3.8.3, 3.7.2, which fixes the issue.&lt;/p&gt;
&lt;p&gt;Alternately ensure the ensemble election/quorum communication is protected by a firewall as this will mitigate the issue.&lt;/p&gt;
&lt;p&gt;See the documentation for more details on correct cluster administration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-zookeeper-2023-44981</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0145 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0145</link>
      <description>certfr-2024-avi-0145</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0145</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-JU62349 — Security fixes for CVE-2018-10237, CVE-2020-8908, CVE-2021-22569, CVE-2021-22570, CVE-2022-3171, CVE-2022-3509, CVE-202…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ju62349</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-hive&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-hive package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-hive&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-hive package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ju62349</guid>
    </item>
    <item>
      <title>EUVD-2026-233203</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-233203</link>
      <description>EUVD-2026-233203</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-233203</guid>
    </item>
    <item>
      <title>fkie_cve-2023-44981</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-44981</link>
      <description>&lt;p&gt;Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if it&amp;#39;s missing, like &amp;#39;eve@EXAMPLE.COM&amp;#39;, the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. Quorum Peer authentication is not enabled by default.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 3.9.1, 3.8.3, 3.7.2, which fixes the issue.&lt;/p&gt;
&lt;p&gt;Alternately ensure the ensemble election/quorum communication is protected by a firewall as this will mitigate the issue.&lt;/p&gt;
&lt;p&gt;See the documentation for more details on correct cluster administration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if it&amp;#39;s missing, like &amp;#39;eve@EXAMPLE.COM&amp;#39;, the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. Quorum Peer authentication is not enabled by default.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 3.9.1, 3.8.3, 3.7.2, which fixes the issue.&lt;/p&gt;
&lt;p&gt;Alternately ensure the ensemble election/quorum communication is protected by a firewall as this will mitigate the issue.&lt;/p&gt;
&lt;p&gt;See the documentation for more details on correct cluster administration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-44981</guid>
    </item>
    <item>
      <title>GHSA-7286-pgfv-vxvh — Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7286-pgfv-vxvh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.zookeeper:zookeeper&lt;/p&gt;
&lt;p&gt;Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if it&amp;#39;s missing, like &amp;#39;eve@EXAMPLE.COM&amp;#39;, the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. Quorum Peer authentication is not enabled by default.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 3.9.1, 3.8.3, 3.7.2, which fixes the issue.&lt;/p&gt;
&lt;p&gt;Alternately ensure the ensemble election/quorum communication is protected by a firewall as this will mitigate the issue.&lt;/p&gt;
&lt;p&gt;See the documentation for more details on correct cluster administration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.zookeeper:zookeeper&lt;/p&gt;
&lt;p&gt;Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if it&amp;#39;s missing, like &amp;#39;eve@EXAMPLE.COM&amp;#39;, the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. Quorum Peer authentication is not enabled by default.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 3.9.1, 3.8.3, 3.7.2, which fixes the issue.&lt;/p&gt;
&lt;p&gt;Alternately ensure the ensemble election/quorum communication is protected by a firewall as this will mitigate the issue.&lt;/p&gt;
&lt;p&gt;See the documentation for more details on correct cluster administration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7286-pgfv-vxvh</guid>
    </item>
    <item>
      <title>gsd-2023-44981</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-44981</link>
      <description>gsd-2023-44981</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-44981</guid>
    </item>
    <item>
      <title>RHSA-2023:7678 — Red Hat Security Advisory: Red Hat AMQ Streams 2.6.0 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:7678</link>
      <description>&lt;p&gt;apache-ivy: XML External Entity vulnerability guava: insecure temporary directory creation JSON-java: parser confusion leads to OOM spring-boot: Security Bypass With Wildcard Pattern Matching on Cloud Foundry jose4j: Insecure iteration count setting bouncycastle: potential  blind LDAP injection attack using a self-signed certificate jetty: Improper validation of HTTP/1 content-length tomcat: Open Redirect vulnerability in FORM authentication gradle: Possible local text file exfiltration by XML External entity injection gradle: Incorrect permission assignment for symlinked files used in copy or archiving operations zookeeper: Authorization Bypass in Apache ZooKeeper&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache-ivy: XML External Entity vulnerability guava: insecure temporary directory creation JSON-java: parser confusion leads to OOM spring-boot: Security Bypass With Wildcard Pattern Matching on Cloud Foundry jose4j: Insecure iteration count setting bouncycastle: potential  blind LDAP injection attack using a self-signed certificate jetty: Improper validation of HTTP/1 content-length tomcat: Open Redirect vulnerability in FORM authentication gradle: Possible local text file exfiltration by XML External entity injection gradle: Incorrect permission assignment for symlinked files used in copy or archiving operations zookeeper: Authorization Bypass in Apache ZooKeeper&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:7678</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-44981</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-44981</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: zookeeper, Ubuntu:20.04:LTS: zookeeper, Ubuntu:22.04:LTS: zookeeper&lt;/p&gt;
&lt;p&gt;Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if it&amp;#39;s missing, like &amp;#39;eve@EXAMPLE.COM&amp;#39;, the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. Quorum Peer authentication is not enabled by default. Users are recommended to upgrade to version 3.9.1, 3.8.3, 3.7.2, which fixes the issue. Alternately ensure the ensemble election/quorum communication is protected by a firewall as this will mitigate the issue. See the documentation for more details on correct cluster administration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: zookeeper, Ubuntu:20.04:LTS: zookeeper, Ubuntu:22.04:LTS: zookeeper&lt;/p&gt;
&lt;p&gt;Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if it&amp;#39;s missing, like &amp;#39;eve@EXAMPLE.COM&amp;#39;, the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. Quorum Peer authentication is not enabled by default. Users are recommended to upgrade to version 3.9.1, 3.8.3, 3.7.2, which fixes the issue. Alternately ensure the ensemble election/quorum communication is protected by a firewall as this will mitigate the issue. See the documentation for more details on correct cluster administration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-44981</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-3070 — Red Hat JBoss A-MQ: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3070</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss A-MQ ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen, Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss A-MQ ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen, Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3070</guid>
    </item>
  </channel>
</rss>
