<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:42:35.958502+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-238483</id>
    <title>EUVD-2026-238483</title>
    <updated>2026-10-03T03:42:36.021613+00:00</updated>
    <content>EUVD-2026-238483</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-238483"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-43435</id>
    <title>fkie_cve-2022-43435</title>
    <updated>2026-10-03T03:42:36.021649+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Jenkins 360 FireLine Plugin 1.7.2 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-43435"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7rrj-hqv6-fvpp</id>
    <title>GHSA-7rrj-hqv6-fvpp — Content-Security-Policy protection for user content can be disabled in Jenkins 360 FireLine Plugin</title>
    <updated>2026-10-03T03:42:36.021681+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.jenkins-ci.plugins.plugin:fireline</p>
<p>Jenkins sets the Content-Security-Policy header to static files served by Jenkins (specifically `DirectoryBrowserSupport`), such as workspaces, `/userContent`, or archived artifacts, unless a Resource Root URL is specified.</p>
<p>360 FireLine Plugin 1.7.2 and earlier globally disables the `Content-Security-Policy` header for static files served by Jenkins whenever the 'Execute FireLine' build step is executed, if the option 'Open access to HTML with JS or CSS' is checked. This allows cross-site scripting (XSS) attacks by users with the ability to control files in workspaces, archived artifacts, etc.</p>
<p>Jenkins instances with [Resource Root URL](https://www.jenkins.io/doc/book/security/user-content/#resource-root-url) configured are unaffected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7rrj-hqv6-fvpp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-43435</id>
    <title>gsd-2022-43435</title>
    <updated>2026-10-03T03:42:36.021783+00:00</updated>
    <content>gsd-2022-43435</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-43435"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1804</id>
    <title>WID-SEC-W-2022-1804 — Jenkins Plugins: Mehrere Schwachstellen</title>
    <updated>2026-10-03T03:42:36.021799+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in verschiedenen Jenkins Plugins ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen oder Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1804"/>
  </entry>
</feed>
