<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:45:19.595106+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-20402</id>
    <title>cnvd-2020-20402</title>
    <updated>2026-10-03T21:45:19.665090+00:00</updated>
    <content>cnvd-2020-20402</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-20402"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-60467</id>
    <title>EUVD-2026-60467</title>
    <updated>2026-10-03T21:45:19.665126+00:00</updated>
    <content>EUVD-2026-60467</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-60467"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-1003011</id>
    <title>fkie_cve-2019-1003011</title>
    <updated>2026-10-03T21:45:19.665139+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An information exposure and denial of service vulnerability exists in Jenkins Token Macro Plugin 2.5 and earlier in src/main/java/org/jenkinsci/plugins/tokenmacro/Parser.java, src/main/java/org/jenkinsci/plugins/tokenmacro/TokenMacro.java, src/main/java/org/jenkinsci/plugins/tokenmacro/impl/AbstractChangesSinceMacro.java, src/main/java/org/jenkinsci/plugins/tokenmacro/impl/ChangesSinceLastBuildMacro.java, src/main/java/org/jenkinsci/plugins/tokenmacro/impl/ProjectUrlMacro.java that allows attackers with the ability to control token macro input (such as SCM changelogs) to define recursive input that results in unexpected macro evaluation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-1003011"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-23h9-m55m-c5jp</id>
    <title>GHSA-23h9-m55m-c5jp — Jenkins Token Macro Plugin's recursive token expansion results in information disclosure and DoS</title>
    <updated>2026-10-03T21:45:19.665169+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.jenkins-ci.plugins:token-macro</p>
<p>Jenkins Token Macro Plugin recursively applied token expansion.</p>
<p>This could be used by users able to affect input to token expansion (such as change log messages), to inject additional tokens into the input, which would then be expanded, resulting in information disclosure (for example values of environment variables), or denial of service.</p>
<p>Most tokens have been changed to no longer recursively apply token expansion.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-23h9-m55m-c5jp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-1003011</id>
    <title>gsd-2019-1003011</title>
    <updated>2026-10-03T21:45:19.665196+00:00</updated>
    <content>gsd-2019-1003011</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-1003011"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2019:0326</id>
    <title>RHBA-2019:0326 — Red Hat Bug Fix Advisory: OpenShift Container Platform 3.11 bug fix update</title>
    <updated>2026-10-03T21:45:19.665208+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>haproxy: Out-of-bounds read in dns.c:dns_validate_dns_response() allows for memory disclosure haproxy: Infinite recursion via crafted packet allows stack exhaustion and denial of service haproxy: Mishandling of priority flag in short HEADERS frame by HTTP/2 decoder allows for crash jenkins-plugin-script-security: Sandbox Bypass in finalize methods jenkins-plugin-script-security: Sandbox Bypass in finalize methods prometheus: Stored DOM cross-site scripting (XSS) attack via crafted URL jenkins-plugin-script-security: Sandbox Bypass in Script Security Plugin jenkins-plugin-workflow-cps: Sandbox Bypass in Pipeline: Groovy Plugin jenkins-plugin-pipeline-model-definition: Sandbox Bypass in Pipeline: Declarative jenkins: cookie crafted using Jenkins script console allows unauthorised access to Jenkins instance jenkins: deleting a user record will does not invalidate existing sessions jenkins-plugin-git: CSRF vulnerability in Git Plugin (SECURITY-1095) jenkins-plugin-token-macro: Recursive token expansion results in information disclosure and DoS in Token Macro Plugin (SECURITY-1102) jenkins-plugin-blueocean: Blue Ocean did not require CSRF tokens (SECURITY-1201) jenkins-plugin-blueocean: XSS vulnerability via user description in Blue Ocean (SECURITY-1204) jenkins-plugin-config-file-provider: Stored XSS vulnerability in Config File Provider Plugin (SECURITY-1253)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2019:0326"/>
  </entry>
</feed>
