<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:14:01 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-00487</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-00487</link>
      <description>bdu:2023-00487</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-00487</guid>
    </item>
    <item>
      <title>EUVD-2026-226623</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-226623</link>
      <description>EUVD-2026-226623</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-226623</guid>
    </item>
    <item>
      <title>fkie_cve-2023-24422</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-24422</link>
      <description>&lt;p&gt;A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-24422</guid>
    </item>
    <item>
      <title>GHSA-76qj-9gwh-pvv3 — Sandbox bypass in Jenkins Script Security Plugin</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-76qj-9gwh-pvv3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.plugins:script-security&lt;/p&gt;
&lt;p&gt;A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.plugins:script-security&lt;/p&gt;
&lt;p&gt;A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-76qj-9gwh-pvv3</guid>
    </item>
    <item>
      <title>gsd-2023-24422</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-24422</link>
      <description>gsd-2023-24422</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-24422</guid>
    </item>
    <item>
      <title>RHSA-2023:1655 — Red Hat Security Advisory: OpenShift Container Platform 4.10.56 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:1655</link>
      <description>&lt;p&gt;kube-apiserver: Aggregated API server can cause clients to be redirected (SSRF) spring-security-oauth2-client: Privilege Escalation in spring-security-oauth2-client spring-security: Authorization rules can be bypassed via forward or include dispatcher types in Spring Security apache-commons-text: variable interpolation RCE jenkins-2-plugins/script-security: Sandbox bypass vulnerability in Script Security Plugin haproxy: request smuggling attack in HTTP/1 header parsing Jenkins: XSS vulnerability in plugin manager Jenkins: Temporary plugin file created with insecure permissions Jenkins: Temporary file parameter created with insecure permissions Jenkins: Information disclosure through error stack traces related to agents&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kube-apiserver: Aggregated API server can cause clients to be redirected (SSRF) spring-security-oauth2-client: Privilege Escalation in spring-security-oauth2-client spring-security: Authorization rules can be bypassed via forward or include dispatcher types in Spring Security apache-commons-text: variable interpolation RCE jenkins-2-plugins/script-security: Sandbox bypass vulnerability in Script Security Plugin haproxy: request smuggling attack in HTTP/1 header parsing Jenkins: XSS vulnerability in plugin manager Jenkins: Temporary plugin file created with insecure permissions Jenkins: Temporary file parameter created with insecure permissions Jenkins: Information disclosure through error stack traces related to agents&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:1655</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0193 — Jenkins Plugins: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0193</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder angemeldeter Angreifer kann mehrere Schwachstellen in Jenkins Plugins ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder angemeldeter Angreifer kann mehrere Schwachstellen in Jenkins Plugins ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0193</guid>
    </item>
  </channel>
</rss>
