<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:57:29.908605+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-197070</id>
    <title>EUVD-2026-197070</title>
    <updated>2026-10-02T14:57:29.913521+00:00</updated>
    <content>EUVD-2026-197070</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-197070"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-39155</id>
    <title>fkie_cve-2023-39155</title>
    <updated>2026-10-02T14:57:29.913562+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-39155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5jc5-m87x-88fj</id>
    <title>GHSA-5jc5-m87x-88fj — Secret displayed without masking by Chef Identity Plugin</title>
    <updated>2026-10-02T14:57:29.913601+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.jenkins-ci.plugins:chef-identity</p>
<p>Chef Identity Plugin stores the user.pem key in its global configuration file `io.chef.jenkins.ChefIdentityBuildWrapper.xml` on the Jenkins controller as part of its configuration.</p>
<p>While this key is stored encrypted on disk, in Chef Identity Plugin 2.0.3 and earlier the global configuration form does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5jc5-m87x-88fj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-39155</id>
    <title>gsd-2023-39155</title>
    <updated>2026-10-02T14:57:29.913639+00:00</updated>
    <content>gsd-2023-39155</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-39155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1902</id>
    <title>WID-SEC-W-2023-1902 — Jenkins: Mehrere Schwachstellen</title>
    <updated>2026-10-02T14:57:29.913657+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen und einen Cross-Site-Scripting-Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1902"/>
  </entry>
</feed>
