<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:41:21 +0000</lastBuildDate>
    <item>
      <title>cnvd-2020-52611</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-52611</link>
      <description>cnvd-2020-52611</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-52611</guid>
    </item>
    <item>
      <title>EUVD-2026-35889</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-35889</link>
      <description>EUVD-2026-35889</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-35889</guid>
    </item>
    <item>
      <title>fkie_cve-2020-2252</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-2252</link>
      <description>&lt;p&gt;Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-2252</guid>
    </item>
    <item>
      <title>GHSA-6fr3-286q-q3cr — Improper Validation of Certificate with Host Mismatch in Jenkins Mailer Plugin</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6fr3-286q-q3cr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.plugins:mailer&lt;/p&gt;
&lt;p&gt;Jenkins Mailer Plugin prior to 1.32.1, 1.31.1, and 1.29.1 does not perform hostname validation when connecting to the configured SMTP server. This lack of validation could be abused using a man-in-the-middle attack to intercept these connections.&lt;/p&gt;
&lt;p&gt;Mailer Plugin 1.32.1, 1.31.1, and 1.29.1 validates the SMTP hostname when connecting via TLS by default. In Mailer Plugin 1.32 and earlier, administrators can set the Java system property mail.smtp.ssl.checkserveridentity to true on startup to enable this protection.&lt;/p&gt;
&lt;p&gt;In case of problems, this protection can be disabled again by setting the Java system property mail.smtp.ssl.checkserveridentity to false on startup.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.plugins:mailer&lt;/p&gt;
&lt;p&gt;Jenkins Mailer Plugin prior to 1.32.1, 1.31.1, and 1.29.1 does not perform hostname validation when connecting to the configured SMTP server. This lack of validation could be abused using a man-in-the-middle attack to intercept these connections.&lt;/p&gt;
&lt;p&gt;Mailer Plugin 1.32.1, 1.31.1, and 1.29.1 validates the SMTP hostname when connecting via TLS by default. In Mailer Plugin 1.32 and earlier, administrators can set the Java system property mail.smtp.ssl.checkserveridentity to true on startup to enable this protection.&lt;/p&gt;
&lt;p&gt;In case of problems, this protection can be disabled again by setting the Java system property mail.smtp.ssl.checkserveridentity to false on startup.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6fr3-286q-q3cr</guid>
    </item>
    <item>
      <title>gsd-2020-2252</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-2252</link>
      <description>gsd-2020-2252</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-2252</guid>
    </item>
    <item>
      <title>RHSA-2020:4297 — Red Hat Security Advisory: OpenShift Container Platform 4.6.1 package security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:4297</link>
      <description>&lt;p&gt;jenkins-jira-plugin: plugin information disclosure jenkins-2-plugins/mailer: Missing hostname validation in Mailer Plugin could result in MITM jenkins-2-plugins/blueocean: Path traversal vulnerability in Blue Ocean Plugin could allow to read arbitrary files jenkins-2-plugins/blueocean: Blue Ocean Plugin does not perform permission checks in several HTTP endpoints implementing connection tests. kubernetes: Docker config secrets leaked when file is malformed and loglevel &amp;gt;= 4 golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash podman: environment variables leak between containers when started via Varlink or Docker-compatible REST API golang: data race in certain net/http servers including ReverseProxy can lead to DoS golang: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jenkins-jira-plugin: plugin information disclosure jenkins-2-plugins/mailer: Missing hostname validation in Mailer Plugin could result in MITM jenkins-2-plugins/blueocean: Path traversal vulnerability in Blue Ocean Plugin could allow to read arbitrary files jenkins-2-plugins/blueocean: Blue Ocean Plugin does not perform permission checks in several HTTP endpoints implementing connection tests. kubernetes: Docker config secrets leaked when file is malformed and loglevel &amp;gt;= 4 golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash podman: environment variables leak between containers when started via Varlink or Docker-compatible REST API golang: data race in certain net/http servers including ReverseProxy can lead to DoS golang: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:4297</guid>
    </item>
  </channel>
</rss>
