<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:40:26 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-01162</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-01162</link>
      <description>bdu:2025-01162</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-01162</guid>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2024-043</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2024-043</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/tfa&lt;/p&gt;
&lt;p&gt;This module enables you to allow and/or require users to use a second authentication method in addition to password authentication.&lt;/p&gt;
&lt;p&gt;The module does not sufficiently migrate sessions before prompting for a second factor token.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must fixate a session on a victim system that is then authenticated with username and password without completing Two Factor authentication. An attacker must gather additional information regarding the entry form after authentication. An attacker must still present a valid token to complete authentication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/tfa&lt;/p&gt;
&lt;p&gt;This module enables you to allow and/or require users to use a second authentication method in addition to password authentication.&lt;/p&gt;
&lt;p&gt;The module does not sufficiently migrate sessions before prompting for a second factor token.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must fixate a session on a victim system that is then authenticated with username and password without completing Two Factor authentication. An attacker must gather additional information regarding the entry form after authentication. An attacker must still present a valid token to complete authentication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2024-043</guid>
    </item>
    <item>
      <title>EUVD-2026-210015</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-210015</link>
      <description>EUVD-2026-210015</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-210015</guid>
    </item>
    <item>
      <title>fkie_cve-2024-13279</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-13279</link>
      <description>&lt;p&gt;Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-13279</guid>
    </item>
    <item>
      <title>GHSA-h6w8-m65g-549g</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h6w8-m65g-549g</link>
      <description>&lt;p&gt;Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h6w8-m65g-549g</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3070 — Drupal: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3070</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Drupal Modulen ausnutzen, um Informationen offenzulegen und Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Drupal Modulen ausnutzen, um Informationen offenzulegen und Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3070</guid>
    </item>
  </channel>
</rss>
