<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:08:42 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-355207</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-355207</link>
      <description>EUVD-2026-355207</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-355207</guid>
    </item>
    <item>
      <title>fkie_cve-2026-71307</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-71307</link>
      <description>&lt;p&gt;Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only on authentication while sibling write handlers required admin_permission. DestinationOutputSchema returned raw options and copied them into pluginOptions without redacting sensitive values. The sftp-destination plugin stored password and privateKeyPass values in plaintext, allowing even a read-only user to retrieve credentials for remote certificate-deployment hosts. The exposed credentials could permit direct access to SFTP systems and TLS material outside the Lemur security boundary. The fix requires administrator permission for destination reads and redacts options marked sensitive. This issue is fixed in version 1.9.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only on authentication while sibling write handlers required admin_permission. DestinationOutputSchema returned raw options and copied them into pluginOptions without redacting sensitive values. The sftp-destination plugin stored password and privateKeyPass values in plaintext, allowing even a read-only user to retrieve credentials for remote certificate-deployment hosts. The exposed credentials could permit direct access to SFTP systems and TLS material outside the Lemur security boundary. The fix requires administrator permission for destination reads and redacts options marked sensitive. This issue is fixed in version 1.9.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-71307</guid>
    </item>
    <item>
      <title>GHSA-6c8m-q6g9-vrw3 — Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passph…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6c8m-q6g9-vrw3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lemur&lt;/p&gt;
&lt;p&gt;### Summary
Lemur&amp;#39;s destination read endpoints -- `GET /api/1/destinations` and `GET /api/1/destinations/&amp;lt;id&amp;gt;` -- return the full set of stored plugin option values to any authenticated user, with no authorization check and no redaction of secret-bearing options. The sibling write endpoints (`POST`/`PUT`/`DELETE`) are gated with `@admin_permission.require(http_exception=403)`, but the two read handlers are protected only by `login_required` (inherited from `AuthenticatedResource`). They do not even exclude `read-only` users.&lt;/p&gt;
&lt;p&gt;The built-in SFTP destination plugin (`sftp-destination`) stores its `password` and `privateKeyPass` options in cleartext in the `destinations.options` column (the plugin&amp;#39;s own docstring states &amp;#34;Passwords are not encrypted and stored as a plain text.&amp;#34;). Because `DestinationOutputSchema` serializes every option value verbatim, any authenticated principal -- including a `read-only` user -- can retrieve these credentials and use them to authenticate to the remote SFTP server to which Lemur deploys certificates.&lt;/p&gt;
&lt;p&gt;### Details
Read endpoints lack the authorization that their write siblings enforce:&lt;/p&gt;
&lt;p&gt;`lemur/destinations/views.py`
```python
class DestinationsList(AuthenticatedResource):
    @validate_schema(None, destinations_output_schema)
    def get(self):                       # &amp;lt;-- only login_required; no admin/read-only gate
        ...
        return service.render(args)&lt;/p&gt;
&lt;p&gt;@validate_schema(destination_input_schema, destination_output_schema)
    @adm…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lemur&lt;/p&gt;
&lt;p&gt;### Summary
Lemur&amp;#39;s destination read endpoints -- `GET /api/1/destinations` and `GET /api/1/destinations/&amp;lt;id&amp;gt;` -- return the full set of stored plugin option values to any authenticated user, with no authorization check and no redaction of secret-bearing options. The sibling write endpoints (`POST`/`PUT`/`DELETE`) are gated with `@admin_permission.require(http_exception=403)`, but the two read handlers are protected only by `login_required` (inherited from `AuthenticatedResource`). They do not even exclude `read-only` users.&lt;/p&gt;
&lt;p&gt;The built-in SFTP destination plugin (`sftp-destination`) stores its `password` and `privateKeyPass` options in cleartext in the `destinations.options` column (the plugin&amp;#39;s own docstring states &amp;#34;Passwords are not encrypted and stored as a plain text.&amp;#34;). Because `DestinationOutputSchema` serializes every option value verbatim, any authenticated principal -- including a `read-only` user -- can retrieve these credentials and use them to authenticate to the remote SFTP server to which Lemur deploys certificates.&lt;/p&gt;
&lt;p&gt;### Details
Read endpoints lack the authorization that their write siblings enforce:&lt;/p&gt;
&lt;p&gt;`lemur/destinations/views.py`
```python
class DestinationsList(AuthenticatedResource):
    @validate_schema(None, destinations_output_schema)
    def get(self):                       # &amp;lt;-- only login_required; no admin/read-only gate
        ...
        return service.render(args)&lt;/p&gt;
&lt;p&gt;@validate_schema(destination_input_schema, destination_output_schema)
    @adm…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6c8m-q6g9-vrw3</guid>
    </item>
    <item>
      <title>PYSEC-2026-3674 — Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passph…</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3674</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lemur&lt;/p&gt;
&lt;p&gt;### Summary
Lemur&amp;#39;s destination read endpoints -- `GET /api/1/destinations` and `GET /api/1/destinations/&amp;lt;id&amp;gt;` -- return the full set of stored plugin option values to any authenticated user, with no authorization check and no redaction of secret-bearing options. The sibling write endpoints (`POST`/`PUT`/`DELETE`) are gated with `@admin_permission.require(http_exception=403)`, but the two read handlers are protected only by `login_required` (inherited from `AuthenticatedResource`). They do not even exclude `read-only` users.&lt;/p&gt;
&lt;p&gt;The built-in SFTP destination plugin (`sftp-destination`) stores its `password` and `privateKeyPass` options in cleartext in the `destinations.options` column (the plugin&amp;#39;s own docstring states &amp;#34;Passwords are not encrypted and stored as a plain text.&amp;#34;). Because `DestinationOutputSchema` serializes every option value verbatim, any authenticated principal -- including a `read-only` user -- can retrieve these credentials and use them to authenticate to the remote SFTP server to which Lemur deploys certificates.&lt;/p&gt;
&lt;p&gt;### Details
Read endpoints lack the authorization that their write siblings enforce:&lt;/p&gt;
&lt;p&gt;`lemur/destinations/views.py`
```python
class DestinationsList(AuthenticatedResource):
    @validate_schema(None, destinations_output_schema)
    def get(self):                       # &amp;lt;-- only login_required; no admin/read-only gate
        ...
        return service.render(args)&lt;/p&gt;
&lt;p&gt;@validate_schema(destination_input_schema, destination_output_schema)
    @adm…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lemur&lt;/p&gt;
&lt;p&gt;### Summary
Lemur&amp;#39;s destination read endpoints -- `GET /api/1/destinations` and `GET /api/1/destinations/&amp;lt;id&amp;gt;` -- return the full set of stored plugin option values to any authenticated user, with no authorization check and no redaction of secret-bearing options. The sibling write endpoints (`POST`/`PUT`/`DELETE`) are gated with `@admin_permission.require(http_exception=403)`, but the two read handlers are protected only by `login_required` (inherited from `AuthenticatedResource`). They do not even exclude `read-only` users.&lt;/p&gt;
&lt;p&gt;The built-in SFTP destination plugin (`sftp-destination`) stores its `password` and `privateKeyPass` options in cleartext in the `destinations.options` column (the plugin&amp;#39;s own docstring states &amp;#34;Passwords are not encrypted and stored as a plain text.&amp;#34;). Because `DestinationOutputSchema` serializes every option value verbatim, any authenticated principal -- including a `read-only` user -- can retrieve these credentials and use them to authenticate to the remote SFTP server to which Lemur deploys certificates.&lt;/p&gt;
&lt;p&gt;### Details
Read endpoints lack the authorization that their write siblings enforce:&lt;/p&gt;
&lt;p&gt;`lemur/destinations/views.py`
```python
class DestinationsList(AuthenticatedResource):
    @validate_schema(None, destinations_output_schema)
    def get(self):                       # &amp;lt;-- only login_required; no admin/read-only gate
        ...
        return service.render(args)&lt;/p&gt;
&lt;p&gt;@validate_schema(destination_input_schema, destination_output_schema)
    @adm…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3674</guid>
    </item>
  </channel>
</rss>
