<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 23:56:23 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-9802 — Conformance validation endpoint discloses detail about service to unauthenticated users</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-9802</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Open Mainframe Project Zowe, linuxfoundation zowe_api_mediation_layer&lt;/p&gt;
&lt;p&gt;The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to an attacker. The attacker could also check if a service is running.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Open Mainframe Project Zowe, linuxfoundation zowe_api_mediation_layer&lt;/p&gt;
&lt;p&gt;The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to an attacker. The attacker could also check if a service is running.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-9802</guid>
    </item>
  </channel>
</rss>
