<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:28:08.407506+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-jenkins-2022-34170</id>
    <title>BIT-jenkins-2022-34170</title>
    <updated>2026-10-03T10:28:08.411679+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: jenkins</p>
<p>In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-jenkins-2022-34170"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-17772</id>
    <title>EUVD-2026-17772</title>
    <updated>2026-10-03T10:28:08.411735+00:00</updated>
    <content>EUVD-2026-17772</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-17772"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-34170</id>
    <title>fkie_cve-2022-34170</title>
    <updated>2026-10-03T10:28:08.411752+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-34170"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-62wf-24c4-8r76</id>
    <title>GHSA-62wf-24c4-8r76 — Cross-site Scripting vulnerability in Jenkins</title>
    <updated>2026-10-03T10:28:08.411774+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.jenkins-ci.main:jenkins-core</p>
<p>Since Jenkins 2.320 and LTS 2.332.1, help icon tooltips no longer escape the feature name, effectively undoing the fix for [SECURITY-1955](https://www.jenkins.io/security/advisory/2020-08-12/#SECURITY-1955).</p>
<p>This vulnerability is known to be exploitable by attackers with Job/Configure permission.</p>
<p>Jenkins 2.356, LTS 2.332.4 and LTS 2.346.1 addresses this vulnerability, the feature name in help icon tooltips is now escaped.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-62wf-24c4-8r76"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-34170</id>
    <title>gsd-2022-34170</title>
    <updated>2026-10-03T10:28:08.411801+00:00</updated>
    <content>gsd-2022-34170</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-34170"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0445</id>
    <title>WID-SEC-W-2022-0445 — Jenkins: Mehrere Schwachstellen</title>
    <updated>2026-10-03T10:28:08.411837+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen und Daten zu manipulieren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0445"/>
  </entry>
</feed>
