<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:57:22 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-197070</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-197070</link>
      <description>EUVD-2026-197070</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-197070</guid>
    </item>
    <item>
      <title>fkie_cve-2023-39155</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-39155</link>
      <description>&lt;p&gt;Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-39155</guid>
    </item>
    <item>
      <title>GHSA-5jc5-m87x-88fj — Secret displayed without masking by Chef Identity Plugin</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5jc5-m87x-88fj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.plugins:chef-identity&lt;/p&gt;
&lt;p&gt;Chef Identity Plugin stores the user.pem key in its global configuration file `io.chef.jenkins.ChefIdentityBuildWrapper.xml` on the Jenkins controller as part of its configuration.&lt;/p&gt;
&lt;p&gt;While this key is stored encrypted on disk, in Chef Identity Plugin 2.0.3 and earlier the global configuration form does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.plugins:chef-identity&lt;/p&gt;
&lt;p&gt;Chef Identity Plugin stores the user.pem key in its global configuration file `io.chef.jenkins.ChefIdentityBuildWrapper.xml` on the Jenkins controller as part of its configuration.&lt;/p&gt;
&lt;p&gt;While this key is stored encrypted on disk, in Chef Identity Plugin 2.0.3 and earlier the global configuration form does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5jc5-m87x-88fj</guid>
    </item>
    <item>
      <title>gsd-2023-39155</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-39155</link>
      <description>gsd-2023-39155</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-39155</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1902 — Jenkins: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1902</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen und einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen und einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1902</guid>
    </item>
  </channel>
</rss>
