<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 19:51:27 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-337127</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337127</link>
      <description>EUVD-2026-337127</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337127</guid>
    </item>
    <item>
      <title>fkie_cve-2024-23683</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-23683</link>
      <description>&lt;p&gt;Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-23683</guid>
    </item>
    <item>
      <title>GHSA-883x-6fch-6wjx — Trust Boundary Violation due to Incomplete Blacklist in Test Failure Processing in Ares</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-883x-6fch-6wjx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: de.tum.in.ase:artemis-java-test-sandbox&lt;/p&gt;
&lt;p&gt;### Impact
This allows an attacker to create special subclasses of `InvocationTargetException` that escape the exception sanitization because JUnit extracts the cause in a trusted context before the exception reaches Ares. This means that arbitrary student code can be executed in a trusted context, and that in turn allows disabling Ares and having full control over the system.&lt;/p&gt;
&lt;p&gt;### Patches
Update to version `1.7.6` or later.&lt;/p&gt;
&lt;p&gt;### Workarounds
Forbid student classes in trusted packages like, e.g., described in https://github.com/ls1intum/Ares/issues/15#issuecomment-996449371&lt;/p&gt;
&lt;p&gt;### References
_Are there any links users can visit to find out more?_
Not that I know of.&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in https://github.com/ls1intum/Ares/issues
* Email us, see https://github.com/ls1intum/Ares/security/policy&lt;/p&gt;
&lt;p&gt;### Detailed description
Using generics, it is possible to throw checked exceptions without a `throws` clause:
&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;ThrowWithoutThrowsHelper&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;```java
public class ThrowWithoutThrowsHelper&amp;lt;X extends Throwable&amp;gt;
{
    private final X throwable;&lt;/p&gt;
&lt;p&gt;private ThrowWithoutThrowsHelper(X throwable)
    {
        this.throwable = throwable;
    }&lt;/p&gt;
&lt;p&gt;private &amp;lt;R&amp;gt; R throwWithThrows() throws X
    {
        throw throwable;
    }&lt;/p&gt;
&lt;p&gt;public static &amp;lt;R&amp;gt; R throwWithoutThrows(Throwable throwable)
    {
        ThrowWithoutThrowsHelper&amp;lt;?&amp;gt; helper = new ThrowWithoutThrowsHelper&amp;lt;Throwable&amp;gt;(throwable);…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: de.tum.in.ase:artemis-java-test-sandbox&lt;/p&gt;
&lt;p&gt;### Impact
This allows an attacker to create special subclasses of `InvocationTargetException` that escape the exception sanitization because JUnit extracts the cause in a trusted context before the exception reaches Ares. This means that arbitrary student code can be executed in a trusted context, and that in turn allows disabling Ares and having full control over the system.&lt;/p&gt;
&lt;p&gt;### Patches
Update to version `1.7.6` or later.&lt;/p&gt;
&lt;p&gt;### Workarounds
Forbid student classes in trusted packages like, e.g., described in https://github.com/ls1intum/Ares/issues/15#issuecomment-996449371&lt;/p&gt;
&lt;p&gt;### References
_Are there any links users can visit to find out more?_
Not that I know of.&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in https://github.com/ls1intum/Ares/issues
* Email us, see https://github.com/ls1intum/Ares/security/policy&lt;/p&gt;
&lt;p&gt;### Detailed description
Using generics, it is possible to throw checked exceptions without a `throws` clause:
&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;ThrowWithoutThrowsHelper&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;```java
public class ThrowWithoutThrowsHelper&amp;lt;X extends Throwable&amp;gt;
{
    private final X throwable;&lt;/p&gt;
&lt;p&gt;private ThrowWithoutThrowsHelper(X throwable)
    {
        this.throwable = throwable;
    }&lt;/p&gt;
&lt;p&gt;private &amp;lt;R&amp;gt; R throwWithThrows() throws X
    {
        throw throwable;
    }&lt;/p&gt;
&lt;p&gt;public static &amp;lt;R&amp;gt; R throwWithoutThrows(Throwable throwable)
    {
        ThrowWithoutThrowsHelper&amp;lt;?&amp;gt; helper = new ThrowWithoutThrowsHelper&amp;lt;Throwable&amp;gt;(throwable);…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-883x-6fch-6wjx</guid>
    </item>
    <item>
      <title>gsd-2024-23683</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-23683</link>
      <description>gsd-2024-23683</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-23683</guid>
    </item>
  </channel>
</rss>
