<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 00:58:15 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-02698</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-02698</link>
      <description>bdu:2020-02698</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-02698</guid>
    </item>
    <item>
      <title>BIT-jenkins-2020-2162</title>
      <link>https://cve.radiocsirt.org/vuln/bit-jenkins-2020-2162</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: jenkins&lt;/p&gt;
&lt;p&gt;Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: jenkins&lt;/p&gt;
&lt;p&gt;Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-jenkins-2020-2162</guid>
    </item>
    <item>
      <title>cnvd-2020-20707</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-20707</link>
      <description>cnvd-2020-20707</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-20707</guid>
    </item>
    <item>
      <title>EUVD-2026-35807</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-35807</link>
      <description>EUVD-2026-35807</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-35807</guid>
    </item>
    <item>
      <title>fkie_cve-2020-2162</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-2162</link>
      <description>&lt;p&gt;Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-2162</guid>
    </item>
    <item>
      <title>GHSA-crg2-6xv3-qg5f — Improper Neutralization of Input During Web Page Generation in Jenkins</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-crg2-6xv3-qg5f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.main:jenkins-core&lt;/p&gt;
&lt;p&gt;Jenkins 2.227 and earlier, LTS 2.204.5 and earlier served files uploaded as file parameters to a build without specifying appropriate `Content-Security-Policy HTTP` headers. This resulted in a stored cross-site scripting (XSS) vulnerability exploitable by users with permissions to build a job with file parameters.\n\nJenkins now sets `Content-Security-Policy` HTTP headers when serving files uploaded via a file parameter to the same value as used for files in workspaces and archived artifacts not served using the Resource Root URL.\n\nThe system property `hudson.model.DirectoryBrowserSupport.CSP` can be set to override the value of `Content-Security-Policy` headers sent when serving these files. This is the same system property used for files in workspaces and archived artifacts unless those are served via the [Resource Root URL](https://www.jenkins.io/doc/upgrade-guide/2.204/#resource-domain-support) and works the same way for file parameters. See [Configuring Content Security Policy](https://www.jenkins.io/doc/book/security/configuring-content-security-policy) to learn more.\n\nEven when Jenkins is configured to serve files in workspaces and archived artifacts using the Resource Root URL (introduced in Jenkins 2.200), file parameters are not, and therefore still subject to `Content-Security-Policy` restrictions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.main:jenkins-core&lt;/p&gt;
&lt;p&gt;Jenkins 2.227 and earlier, LTS 2.204.5 and earlier served files uploaded as file parameters to a build without specifying appropriate `Content-Security-Policy HTTP` headers. This resulted in a stored cross-site scripting (XSS) vulnerability exploitable by users with permissions to build a job with file parameters.\n\nJenkins now sets `Content-Security-Policy` HTTP headers when serving files uploaded via a file parameter to the same value as used for files in workspaces and archived artifacts not served using the Resource Root URL.\n\nThe system property `hudson.model.DirectoryBrowserSupport.CSP` can be set to override the value of `Content-Security-Policy` headers sent when serving these files. This is the same system property used for files in workspaces and archived artifacts unless those are served via the [Resource Root URL](https://www.jenkins.io/doc/upgrade-guide/2.204/#resource-domain-support) and works the same way for file parameters. See [Configuring Content Security Policy](https://www.jenkins.io/doc/book/security/configuring-content-security-policy) to learn more.\n\nEven when Jenkins is configured to serve files in workspaces and archived artifacts using the Resource Root URL (introduced in Jenkins 2.200), file parameters are not, and therefore still subject to `Content-Security-Policy` restrictions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-crg2-6xv3-qg5f</guid>
    </item>
    <item>
      <title>gsd-2020-2162</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-2162</link>
      <description>gsd-2020-2162</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-2162</guid>
    </item>
    <item>
      <title>RHBA-2020:2435 — Red Hat Bug Fix Advisory: OpenShift Container Platform 4.3.25 packages update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2020:2435</link>
      <description>&lt;p&gt;jenkins: CSRF protection bypass via crafted URLs jenkins: XSS in job configuration pages jenkins: Content-Security-Policy headers for files uploaded leads to XSS jenkins: improperly processes HTML content of list leads to XSS&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jenkins: CSRF protection bypass via crafted URLs jenkins: XSS in job configuration pages jenkins: Content-Security-Policy headers for files uploaded leads to XSS jenkins: improperly processes HTML content of list leads to XSS&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2020:2435</guid>
    </item>
  </channel>
</rss>
