<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:41:41 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-02143</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-02143</link>
      <description>bdu:2024-02143</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-02143</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0232 — Une vulnérabilité a été découverte dans &lt;span class="textit"&gt;les
produits Spring Security&lt;/span&gt;. Elle permet à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0232</link>
      <description>certfr-2024-avi-0232</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0232</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-GZ54612 — In Spring Security, versions 5</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-gz54612</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-nifi package. In Spring Security, versions 5. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-nifi package. In Spring Security, versions 5. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-gz54612</guid>
    </item>
    <item>
      <title>EUVD-2026-331355</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-331355</link>
      <description>EUVD-2026-331355</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-331355</guid>
    </item>
    <item>
      <title>fkie_cve-2024-22257</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-22257</link>
      <description>&lt;p&gt;In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 
5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, 
versions 6.2.x prior to 6.2.3, an application is possible vulnerable to 
broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 
5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, 
versions 6.2.x prior to 6.2.3, an application is possible vulnerable to 
broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-22257</guid>
    </item>
    <item>
      <title>GHSA-f3jh-qvm4-mg39 — Erroneous authentication pass in Spring Security</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f3jh-qvm4-mg39</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework.security:spring-security-core&lt;/p&gt;
&lt;p&gt;In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.&lt;/p&gt;
&lt;p&gt;Specifically, an application is vulnerable if:&lt;/p&gt;
&lt;p&gt;The application uses AuthenticatedVoter directly and a null authentication parameter is passed to it resulting in an erroneous true return value.&lt;/p&gt;
&lt;p&gt;An application is not vulnerable if any of the following is true:&lt;/p&gt;
&lt;p&gt;* The application does not use AuthenticatedVoter#vote directly.
* The application does not pass null to AuthenticatedVoter#vote.&lt;/p&gt;
&lt;p&gt;Note that AuthenticatedVoter is deprecated since 5.8, use implementations of AuthorizationManager as a replacement.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework.security:spring-security-core&lt;/p&gt;
&lt;p&gt;In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.&lt;/p&gt;
&lt;p&gt;Specifically, an application is vulnerable if:&lt;/p&gt;
&lt;p&gt;The application uses AuthenticatedVoter directly and a null authentication parameter is passed to it resulting in an erroneous true return value.&lt;/p&gt;
&lt;p&gt;An application is not vulnerable if any of the following is true:&lt;/p&gt;
&lt;p&gt;* The application does not use AuthenticatedVoter#vote directly.
* The application does not pass null to AuthenticatedVoter#vote.&lt;/p&gt;
&lt;p&gt;Note that AuthenticatedVoter is deprecated since 5.8, use implementations of AuthorizationManager as a replacement.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f3jh-qvm4-mg39</guid>
    </item>
    <item>
      <title>gsd-2024-22257</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-22257</link>
      <description>gsd-2024-22257</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-22257</guid>
    </item>
    <item>
      <title>RHSA-2024:3354 — Red Hat Security Advisory: Red Hat Fuse 7.13.0 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:3354</link>
      <description>&lt;p&gt;ActiveMQ: Deserialization vulnerability on Jolokia that allows authenticated users to perform RCE undertow: OutOfMemoryError due to @MultipartConfig handling JSON-java: parser confusion leads to OOM logback: serialization vulnerability in logback receiver logback: A serialization vulnerability in logback receiver spring-boot: org.springframework.boot: spring-boot-actuator class vulnerable to denial of service jetty: hpack header values cause denial of service in http/2 jetty: Improper addition of quotation marks to user inputs in CgiServlet apache-avro: Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK jetty: Improper validation of HTTP/1 content-length tomcat: HTTP request smuggling via malformed trailer headers shiro: path traversal attack may lead to authentication bypass Solr: Host environment variables are published via the Metrics API undertow: Out-of-memory Error after several closed connections with wildfly-http-client protocol tomcat: Leaking of unrelated request bodies in default error page springframework: URL Parsing with Host Validation spring-security: Broken Access Control With Direct Use of AuthenticatedVoter cxf-core: Apache CXF SSRF Vulnerability using the Aegis databinding&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ActiveMQ: Deserialization vulnerability on Jolokia that allows authenticated users to perform RCE undertow: OutOfMemoryError due to @MultipartConfig handling JSON-java: parser confusion leads to OOM logback: serialization vulnerability in logback receiver logback: A serialization vulnerability in logback receiver spring-boot: org.springframework.boot: spring-boot-actuator class vulnerable to denial of service jetty: hpack header values cause denial of service in http/2 jetty: Improper addition of quotation marks to user inputs in CgiServlet apache-avro: Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK jetty: Improper validation of HTTP/1 content-length tomcat: HTTP request smuggling via malformed trailer headers shiro: path traversal attack may lead to authentication bypass Solr: Host environment variables are published via the Metrics API undertow: Out-of-memory Error after several closed connections with wildfly-http-client protocol tomcat: Leaking of unrelated request bodies in default error page springframework: URL Parsing with Host Validation spring-security: Broken Access Control With Direct Use of AuthenticatedVoter cxf-core: Apache CXF SSRF Vulnerability using the Aegis databinding&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:3354</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0658 — VMware Tanzu Spring Security: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0658</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in VMware Tanzu Spring Security ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in VMware Tanzu Spring Security ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0658</guid>
    </item>
  </channel>
</rss>
