<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:28:04 +0000</lastBuildDate>
    <item>
      <title>BIT-jenkins-2022-34170</title>
      <link>https://cve.radiocsirt.org/vuln/bit-jenkins-2022-34170</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: jenkins&lt;/p&gt;
&lt;p&gt;In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: jenkins&lt;/p&gt;
&lt;p&gt;In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-jenkins-2022-34170</guid>
    </item>
    <item>
      <title>EUVD-2026-17772</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-17772</link>
      <description>EUVD-2026-17772</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-17772</guid>
    </item>
    <item>
      <title>fkie_cve-2022-34170</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-34170</link>
      <description>&lt;p&gt;In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-34170</guid>
    </item>
    <item>
      <title>GHSA-62wf-24c4-8r76 — Cross-site Scripting vulnerability in Jenkins</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-62wf-24c4-8r76</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.main:jenkins-core&lt;/p&gt;
&lt;p&gt;Since Jenkins 2.320 and LTS 2.332.1, help icon tooltips no longer escape the feature name, effectively undoing the fix for [SECURITY-1955](https://www.jenkins.io/security/advisory/2020-08-12/#SECURITY-1955).&lt;/p&gt;
&lt;p&gt;This vulnerability is known to be exploitable by attackers with Job/Configure permission.&lt;/p&gt;
&lt;p&gt;Jenkins 2.356, LTS 2.332.4 and LTS 2.346.1 addresses this vulnerability, the feature name in help icon tooltips is now escaped.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.main:jenkins-core&lt;/p&gt;
&lt;p&gt;Since Jenkins 2.320 and LTS 2.332.1, help icon tooltips no longer escape the feature name, effectively undoing the fix for [SECURITY-1955](https://www.jenkins.io/security/advisory/2020-08-12/#SECURITY-1955).&lt;/p&gt;
&lt;p&gt;This vulnerability is known to be exploitable by attackers with Job/Configure permission.&lt;/p&gt;
&lt;p&gt;Jenkins 2.356, LTS 2.332.4 and LTS 2.346.1 addresses this vulnerability, the feature name in help icon tooltips is now escaped.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-62wf-24c4-8r76</guid>
    </item>
    <item>
      <title>gsd-2022-34170</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-34170</link>
      <description>gsd-2022-34170</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-34170</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0445 — Jenkins: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0445</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen und Daten zu manipulieren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen und Daten zu manipulieren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0445</guid>
    </item>
  </channel>
</rss>
