<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 15:59:03 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:2293 — Moderate: pki-core security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:2293</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: idm-pki-acme, AlmaLinux:9: idm-pki-base, AlmaLinux:9: idm-pki-ca, AlmaLinux:9: idm-pki-est, AlmaLinux:9: idm-pki-java, AlmaLinux:9: idm-pki-kra, AlmaLinux:9: idm-pki-server, AlmaLinux:9: idm-pki-tools, AlmaLinux:9: python3-idm-pki&lt;/p&gt;
&lt;p&gt;The Public Key Infrastructure (PKI) Core contains fundamental packages required by AlmaLinux Certificate System.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field (CVE-2022-2393)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: idm-pki-acme, AlmaLinux:9: idm-pki-base, AlmaLinux:9: idm-pki-ca, AlmaLinux:9: idm-pki-est, AlmaLinux:9: idm-pki-java, AlmaLinux:9: idm-pki-kra, AlmaLinux:9: idm-pki-server, AlmaLinux:9: idm-pki-tools, AlmaLinux:9: python3-idm-pki&lt;/p&gt;
&lt;p&gt;The Public Key Infrastructure (PKI) Core contains fundamental packages required by AlmaLinux Certificate System.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field (CVE-2022-2393)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:2293</guid>
    </item>
    <item>
      <title>EUVD-2026-12368</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-12368</link>
      <description>EUVD-2026-12368</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-12368</guid>
    </item>
    <item>
      <title>fkie_cve-2022-2393</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-2393</link>
      <description>&lt;p&gt;A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-2393</guid>
    </item>
    <item>
      <title>GHSA-hjh3-jq28-5qcc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hjh3-jq28-5qcc</link>
      <description>&lt;p&gt;A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hjh3-jq28-5qcc</guid>
    </item>
    <item>
      <title>gsd-2022-2393</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-2393</link>
      <description>gsd-2022-2393</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-2393</guid>
    </item>
    <item>
      <title>RHSA-2022:7077 — Red Hat Security Advisory: Red Hat Certificate System 9.7 CVE bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:7077</link>
      <description>&lt;p&gt;pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:7077</guid>
    </item>
    <item>
      <title>RHSA-2022:7086 — Red Hat Security Advisory: pki-core security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:7086</link>
      <description>&lt;p&gt;pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:7086</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-2393</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2393</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: dogtag-pki, Ubuntu:Pro:18.04:LTS: dogtag-pki, Ubuntu:Pro:20.04:LTS: dogtag-pki, Ubuntu:Pro:22.04:LTS: dogtag-pki&lt;/p&gt;
&lt;p&gt;A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: dogtag-pki, Ubuntu:Pro:18.04:LTS: dogtag-pki, Ubuntu:Pro:20.04:LTS: dogtag-pki, Ubuntu:Pro:22.04:LTS: dogtag-pki&lt;/p&gt;
&lt;p&gt;A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2393</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0706 — Red Hat Enterprise Linux: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0706</link>
      <description>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0706</guid>
    </item>
  </channel>
</rss>
