<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:54:28.069967+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-49957</id>
    <title>cnvd-2022-49957</title>
    <updated>2026-10-02T23:54:28.089003+00:00</updated>
    <content>cnvd-2022-49957</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-49957"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-16750</id>
    <title>EUVD-2026-16750</title>
    <updated>2026-10-02T23:54:28.089040+00:00</updated>
    <content>EUVD-2026-16750</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-16750"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-30952</id>
    <title>fkie_cve-2022-30952</title>
    <updated>2026-10-02T23:54:28.089054+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-specified IDs stored in the private per-user credentials stores of any attacker-specified user in Jenkins.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-30952"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g74w-93cp-5p3p</id>
    <title>GHSA-g74w-93cp-5p3p — Insufficiently Protected Credentials in Jenkins Pipeline SCM API for Blue Ocean Plugin</title>
    <updated>2026-10-02T23:54:28.089081+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: io.jenkins.blueocean:blueocean-pipeline-scm-api</p>
<p>When pipelines are created using the pipeline creation wizard in Blue Ocean, the credentials used are stored in the per-user credentials store of the user creating the pipeline. To allow pipelines to use this credential to scan repositories and checkout from SCM, the Blue Ocean Credentials Provider allows pipelines to access a specific credential from the per-user credentials store in Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier.</p>
<p>As a result, attackers with Job/Configure permission can rewrite job configurations in a way that lets them access and capture any attacker-specified credential from any user’s private credentials store.</p>
<p>Pipeline SCM API for Blue Ocean Plugin 1.25.4 deprecates the Blue Ocean Credentials Provider and disables it by default. As a result, all jobs initially set up using the Blue Ocean pipeline creation wizard and configured to use the credential specified at that time will no longer be able to access the credential, resulting in failures to scan repositories, checkout from SCM, etc. unless the repository is public and can be accessed without credentials.</p>
<p>This also applies to newly created pipelines after Pipeline SCM API for Blue Ocean Plugin has been updated to 1.25.4.</p>
<p>Administrators should reconfigure affected pipelines to use a credential from the Jenkins credential store or a folder credential store. See [this help page on cloudbees.com](https://cloudbees.com/r/blue-ocean-credentials-removal) to learn more.</p>
<p>To re-enable the Blue O…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g74w-93cp-5p3p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-30952</id>
    <title>gsd-2022-30952</title>
    <updated>2026-10-02T23:54:28.089127+00:00</updated>
    <content>gsd-2022-30952</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-30952"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:0017</id>
    <title>RHSA-2023:0017 — Red Hat Security Advisory: OpenShift Container Platform 4.8.56 packages and security update</title>
    <updated>2026-10-02T23:54:28.089139+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>http2-server: Invalid HTTP/2 requests cause DoS Libraries: Untrusted users can modify some Pipeline libraries in Pipeline Shared Groovy Libraries Plugin plugin: Sandbox bypass vulnerability through implicitly allowlisted platform Groovy files in Pipeline: Groovy Plugin plugin: CSRF vulnerability in Script Security Plugin plugin: Mercurial SCM plugin can check out from the controller file system plugin: User-scoped credentials exposed to other users by Pipeline SCM API for Blue Ocean Plugin plugin: CSRF vulnerability in Blue Ocean Plugin plugin: missing permission checks in Blue Ocean Plugin jenkins: Observable timing discrepancy allows determining username validity jenkins-plugin/junit: Stored XSS vulnerability in JUnit Plugin jenkins-plugin: Arbitrary file write vulnerability in Pipeline Input Step Plugin jenkins-plugin: Man-in-the-Middle (MitM) in org.jenkins-ci.plugins:git-client jenkins-plugin: Cross-site Request Forgery (CSRF) in org.jenkins-ci.plugins:git plugin: Lack of authentication mechanism in Git Plugin webhook plugin: Lack of authentication mechanism in Git Plugin webhook plugin: Non-constant time webhook signature comparison in GitHub Plugin</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:0017"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0090</id>
    <title>WID-SEC-W-2023-0090 — Jenkins: Mehrere Schwachstellen</title>
    <updated>2026-10-02T23:54:28.089172+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, vertrauliche Informationen offenzulegen und Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0090"/>
  </entry>
</feed>
