<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T19:17:55.417481+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-260077</id>
    <title>EUVD-2026-260077</title>
    <updated>2026-10-10T19:17:55.467164+00:00</updated>
    <content>EUVD-2026-260077</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-260077"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64132</id>
    <title>fkie_cve-2025-64132</title>
    <updated>2026-10-10T19:17:55.467210+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger builds and obtain information about job and cloud configuration they should not be able to access.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-64132"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mrpq-9jr3-rqq9</id>
    <title>GHSA-mrpq-9jr3-rqq9 — Jenkins MCP Server Plugin does not perform permission checks in multiple MCP tools</title>
    <updated>2026-10-10T19:17:55.467259+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: io.jenkins.plugins:mcp-server</p>
<p>Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in several MCP tools.</p>
<p>This allows to do the following:</p>
<p>- Attackers with Item/Read permission can obtain information about the configured SCM in a job despite lacking Item/Extended Read permission (`getJobScm`).</p>
<p>- Attackers with Item/Read permission can trigger new builds of a job despite lacking Item/Build permission (`triggerBuild`).</p>
<p>- Attackers without Overall/Read permission can retrieve the names of configured clouds (`getStatus`).</p>
<p>MCP Server Plugin 0.86.v7d3355e6a_a_18 performs permission checks for the affected MCP tools.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mrpq-9jr3-rqq9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2443</id>
    <title>WID-SEC-W-2025-2443 — Jenkins Plugins: Mehrere Schwachstellen</title>
    <updated>2026-10-10T19:17:55.467292+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen und serverseitige Request-Forgery durchzuführen</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2443"/>
  </entry>
</feed>
