<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:45:08.199399+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-236057</id>
    <title>EUVD-2026-236057</title>
    <updated>2026-10-03T19:45:08.282016+00:00</updated>
    <content>EUVD-2026-236057</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-236057"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-45388</id>
    <title>fkie_cve-2022-45388</title>
    <updated>2026-10-03T19:45:08.282057+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Jenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing unauthenticated attackers to read arbitrary files with '.xml' extension on the Jenkins controller file system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-45388"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9pqq-h9qv-28fp</id>
    <title>GHSA-9pqq-h9qv-28fp — Jenkins Config Rotator Plugin vulnerable to path traversal</title>
    <updated>2026-10-03T19:45:08.282092+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.jenkins-ci.main:config-rotator</p>
<p>Jenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing unauthenticated attackers to read arbitrary files with '.xml' extension on the Jenkins controller file system. Currently there is no known workaround and no fix available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9pqq-h9qv-28fp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-45388</id>
    <title>gsd-2022-45388</title>
    <updated>2026-10-03T19:45:08.282119+00:00</updated>
    <content>gsd-2022-45388</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-45388"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2056</id>
    <title>WID-SEC-W-2022-2056 — Jenkins: Mehrere Schwachstellen</title>
    <updated>2026-10-03T19:45:08.282131+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer, authentisierter oder lokaler  Angreifer kann mehrere Schwachstellen in verschiedenen Jenkins Plugins ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und einen Cross-Site-Scripting-Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2056"/>
  </entry>
</feed>
