<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:52:39 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-07713</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-07713</link>
      <description>bdu:2024-07713</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-07713</guid>
    </item>
    <item>
      <title>EUVD-2026-351117</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-351117</link>
      <description>EUVD-2026-351117</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-351117</guid>
    </item>
    <item>
      <title>fkie_cve-2024-7387</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-7387</link>
      <description>&lt;p&gt;A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the “Docker” strategy, executable files inside the privileged build container can be overridden using the `spec.source.secrets.secret.destinationDir` attribute of the `BuildConfig` definition. An attacker running code in a privileged container could escalate their permissions on the node running the container.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the “Docker” strategy, executable files inside the privileged build container can be overridden using the `spec.source.secrets.secret.destinationDir` attribute of the `BuildConfig` definition. An attacker running code in a privileged container could escalate their permissions on the node running the container.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-7387</guid>
    </item>
    <item>
      <title>GHSA-qqv8-ph7f-h3f7 — OpenShift Builder has a path traversal, allows command injection in privileged BuildContainer</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qqv8-ph7f-h3f7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/openshift/builder&lt;/p&gt;
&lt;p&gt;A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the &amp;#34;Docker&amp;#34; strategy, executable files inside the privileged build container can be overridden using the `spec.source.secrets.secret.destinationDir` attribute of the `BuildConfig` definition. An attacker running code in a privileged container could escalate their permissions on the node running the container.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/openshift/builder&lt;/p&gt;
&lt;p&gt;A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the &amp;#34;Docker&amp;#34; strategy, executable files inside the privileged build container can be overridden using the `spec.source.secrets.secret.destinationDir` attribute of the `BuildConfig` definition. An attacker running code in a privileged container could escalate their permissions on the node running the container.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qqv8-ph7f-h3f7</guid>
    </item>
    <item>
      <title>RHSA-2024:3718 — Red Hat Security Advisory: OpenShift Container Platform 4.17.0 bug fix and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:3718</link>
      <description>&lt;p&gt;hashicorp/vault: vault enterprise’s sentinel RGP policies allowed for cross-namespace denial of service hashicorp/vault: Google Cloud Secrets Engine Removed Existing IAM Conditions When Creating / Updating Rolesets vault: inbound client requests can trigger a denial of service ssh: Prefix truncation attack on Binary Packet Protocol (BPP) containers/image: digest type does not guarantee valid type openshift/builder: Path traversal allows command injection in privileged BuildContainer using docker build strategy golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON golang: archive/zip: Incorrect handling of certain ZIP files helm: Dependency management path traversal jose-go: improper handling of highly compressed data openshift-controller-manager: Elevated Build Pods Can Lead to Node Compromise in OpenShift&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;hashicorp/vault: vault enterprise’s sentinel RGP policies allowed for cross-namespace denial of service hashicorp/vault: Google Cloud Secrets Engine Removed Existing IAM Conditions When Creating / Updating Rolesets vault: inbound client requests can trigger a denial of service ssh: Prefix truncation attack on Binary Packet Protocol (BPP) containers/image: digest type does not guarantee valid type openshift/builder: Path traversal allows command injection in privileged BuildContainer using docker build strategy golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON golang: archive/zip: Incorrect handling of certain ZIP files helm: Dependency management path traversal jose-go: improper handling of highly compressed data openshift-controller-manager: Elevated Build Pods Can Lead to Node Compromise in OpenShift&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:3718</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-2174 — Red Hat OpenShift: Mehrere Schwachstellen ermöglichen Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2174</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2174</guid>
    </item>
  </channel>
</rss>
