<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:02:18 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-175557</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-175557</link>
      <description>EUVD-2026-175557</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-175557</guid>
    </item>
    <item>
      <title>fkie_cve-2012-5055</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2012-5055</link>
      <description>&lt;p&gt;DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2012-5055</guid>
    </item>
    <item>
      <title>GHSA-3533-rvpc-6x56 — Exposure of Sensitive Information to an Unauthorized Actor in Spring Security</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3533-rvpc-6x56</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework.security:spring-security-core&lt;/p&gt;
&lt;p&gt;DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework.security:spring-security-core&lt;/p&gt;
&lt;p&gt;DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3533-rvpc-6x56</guid>
    </item>
    <item>
      <title>gsd-2012-5055</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2012-5055</link>
      <description>gsd-2012-5055</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2012-5055</guid>
    </item>
    <item>
      <title>RHSA-2013:0649 — Red Hat Security Advisory: Fuse ESB Enterprise 7.1.0 update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2013:0649</link>
      <description>&lt;p&gt;Security: Ability to determine if username is valid via DaoAuthenticationProvider apache-cxf: Bypass of security constraints on WS endpoints when using WSS4JInInterceptor apache-cxf: UsernameTokenPolicyValidator and UsernameTokenInterceptor allow empty passwords to authenticate&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security: Ability to determine if username is valid via DaoAuthenticationProvider apache-cxf: Bypass of security constraints on WS endpoints when using WSS4JInInterceptor apache-cxf: UsernameTokenPolicyValidator and UsernameTokenInterceptor allow empty passwords to authenticate&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2013:0649</guid>
    </item>
  </channel>
</rss>
