<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 02:05:18 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-211662</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-211662</link>
      <description>EUVD-2026-211662</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-211662</guid>
    </item>
    <item>
      <title>fkie_cve-2023-32981</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-32981</link>
      <description>&lt;p&gt;An arbitrary file write vulnerability in Jenkins Pipeline Utility Steps Plugin 2.15.2 and earlier allows attackers able to provide crafted archives as parameters to create or replace arbitrary files on the agent file system with attacker-specified content.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An arbitrary file write vulnerability in Jenkins Pipeline Utility Steps Plugin 2.15.2 and earlier allows attackers able to provide crafted archives as parameters to create or replace arbitrary files on the agent file system with attacker-specified content.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-32981</guid>
    </item>
    <item>
      <title>GHSA-6987-xccv-fhjp — Jenkins Pipeline Utility Steps Plugin arbitrary file write vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6987-xccv-fhjp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.plugins:pipeline-utility-steps&lt;/p&gt;
&lt;p&gt;Jenkins Pipeline Utility Steps Plugin provides the `untar` and `unzip` Pipeline steps to extract archives into job workspaces.&lt;/p&gt;
&lt;p&gt;Pipeline Utility Steps Plugin 2.15.2 and earlier does not validate or limit file paths of files contained within these archives.&lt;/p&gt;
&lt;p&gt;This allows attackers able to provide crafted archives as parameters to create or replace arbitrary files on the agent file system with attacker-specified content.&lt;/p&gt;
&lt;p&gt;Pipeline Utility Steps Plugin 2.15.3 rejects extraction of files in `tar` and `zip` archives that would be placed outside the expected destination directory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.plugins:pipeline-utility-steps&lt;/p&gt;
&lt;p&gt;Jenkins Pipeline Utility Steps Plugin provides the `untar` and `unzip` Pipeline steps to extract archives into job workspaces.&lt;/p&gt;
&lt;p&gt;Pipeline Utility Steps Plugin 2.15.2 and earlier does not validate or limit file paths of files contained within these archives.&lt;/p&gt;
&lt;p&gt;This allows attackers able to provide crafted archives as parameters to create or replace arbitrary files on the agent file system with attacker-specified content.&lt;/p&gt;
&lt;p&gt;Pipeline Utility Steps Plugin 2.15.3 rejects extraction of files in `tar` and `zip` archives that would be placed outside the expected destination directory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6987-xccv-fhjp</guid>
    </item>
    <item>
      <title>gsd-2023-32981</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-32981</link>
      <description>gsd-2023-32981</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-32981</guid>
    </item>
    <item>
      <title>RHSA-2023:3610 — Red Hat Security Advisory: jenkins and jenkins-2-plugins security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:3610</link>
      <description>&lt;p&gt;jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode maven-shared-utils: Command injection via Commandline class plugin: CSRF vulnerability in Blue Ocean Plugin plugin: missing permission checks in Blue Ocean Plugin jettison: parser crash by stackoverflow jettison: memory exhaustion via user-supplied XML or JSON data jettison: If the value in map is the map&amp;#39;s self, the new new JSONObject(map) cause StackOverflowError which may lead to dos json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) springframework: Security Bypass With Un-Prefixed Double Wildcard Pattern springframework: Spring Expression DoS Vulnerability jenkins-2-plugins/script-security: Sandbox bypass vulnerability in Script Security Plugin jenkins-2-plugin: workflow-job: Stored XSS vulnerability in Pipeline: Job Plugin jenkins-2-plugin: pipeline-utility-steps: Arbitrary file write vulnerability on agents in Pipeline Utility Steps Plugin&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode maven-shared-utils: Command injection via Commandline class plugin: CSRF vulnerability in Blue Ocean Plugin plugin: missing permission checks in Blue Ocean Plugin jettison: parser crash by stackoverflow jettison: memory exhaustion via user-supplied XML or JSON data jettison: If the value in map is the map&amp;#39;s self, the new new JSONObject(map) cause StackOverflowError which may lead to dos json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) springframework: Security Bypass With Un-Prefixed Double Wildcard Pattern springframework: Spring Expression DoS Vulnerability jenkins-2-plugins/script-security: Sandbox bypass vulnerability in Script Security Plugin jenkins-2-plugin: workflow-job: Stored XSS vulnerability in Pipeline: Job Plugin jenkins-2-plugin: pipeline-utility-steps: Arbitrary file write vulnerability on agents in Pipeline Utility Steps Plugin&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:3610</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1228 — Jenkins Plugins: Mehrere Schwachstellen ermöglichen Manipulation von Dateien</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1228</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in verschiedenen Jenkins Plugins ausnutzen, um einen Cross-Site-Scripting-Angriff-durchzuführen, Dateien zu manipulieren, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen oder einen Cross-Site-Request-Forgery-Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in verschiedenen Jenkins Plugins ausnutzen, um einen Cross-Site-Scripting-Angriff-durchzuführen, Dateien zu manipulieren, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen oder einen Cross-Site-Request-Forgery-Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1228</guid>
    </item>
  </channel>
</rss>
