<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:27:07.009975+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-22159</id>
    <title>cnvd-2021-22159</title>
    <updated>2026-10-03T18:27:07.090081+00:00</updated>
    <content>cnvd-2021-22159</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-22159"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-22332</id>
    <title>EUVD-2026-22332</title>
    <updated>2026-10-03T18:27:07.090122+00:00</updated>
    <content>EUVD-2026-22332</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-22332"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-21623</id>
    <title>fkie_cve-2021-21623</title>
    <updated>2026-10-03T18:27:07.090136+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-21623"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-96jw-3xw4-mq9p</id>
    <title>GHSA-96jw-3xw4-mq9p — Incorrect permission checks in Jenkins Matrix Authorization Strategy Plugin may allow accessing some items</title>
    <updated>2026-10-03T18:27:07.090165+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.jenkins-ci.plugins:matrix-auth</p>
<p>Items (like jobs) can be organized hierarchically in Jenkins, using the Folders Plugin or something similar. An item is expected to be accessible only if all its ancestors are accessible as well.</p>
<p>Matrix Authorization Strategy Plugin 2.6.5 and earlier does not correctly perform permission checks to determine whether an item should be accessible.</p>
<p>This allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.\n\nMatrix Authorization Strategy Plugin 2.6.6 requires Item/Read permission on parent items to grant Item/Read permission on an individual item.</p>
<p>As a workaround in older releases, do not grant permissions on individual items to users who do not have access to parent items.</p>
<p>In case of problems, the [Java system property](https://www.jenkins.io/doc/book/managing/system-properties/) `hudson.security.AuthorizationMatrixProperty.checkParentPermissions` can be set to false, completely disabling this fix.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-96jw-3xw4-mq9p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-21623</id>
    <title>gsd-2021-21623</title>
    <updated>2026-10-03T18:27:07.090197+00:00</updated>
    <content>gsd-2021-21623</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-21623"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:2437</id>
    <title>RHSA-2021:2437 — Red Hat Security Advisory: OpenShift Container Platform 4.8.2 packages and security update</title>
    <updated>2026-10-03T18:27:07.090208+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: crypto/elliptic: incorrect operations on the P-224 curve gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation openshift: Injected service-ca.crt incorrectly contains additional internal CAs containers/storage: DoS via malicious image python-eventlet: improper handling of highly compressed data and memory allocation with excessive size allows DoS jenkins: Arbitrary file read vulnerability in workspace browsers jenkins: XSS vulnerability in notification bar jenkins: Improper handling of REST API XML deserialization errors jenkins: Path traversal vulnerability in agent names jenkins: Arbitrary file existence check in file fingerprints jenkins: Excessive memory allocation in graph URLs leads to denial of service jenkins: Stored XSS vulnerability in button labels jenkins: Missing permission check for paths with specific prefix jenkins: Reflected XSS vulnerability in markup formatter preview jenkins: Stored XSS vulnerability on new item page jenkins-2-plugins/matrix-auth: Incorrect permission checks in Matrix Authorization Strategy Plugin jenkins: lack of type validation in agent related REST API jenkins: view name validation bypass jenkins-2-plugins/config-file-provider: Does not configure its XML parser to prevent XML external entity (XXE) attacks. jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints. jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:2437"/>
  </entry>
</feed>
