<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:09:46 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-00899</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-00899</link>
      <description>bdu:2024-00899</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-00899</guid>
    </item>
    <item>
      <title>EUVD-2026-242972</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-242972</link>
      <description>EUVD-2026-242972</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-242972</guid>
    </item>
    <item>
      <title>fkie_cve-2024-23899</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-23899</link>
      <description>&lt;p&gt;Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an &amp;#39;@&amp;#39; character followed by a file path in an argument with the file&amp;#39;s contents, allowing attackers with Overall/Read permission to read content from arbitrary files on the Jenkins controller file system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an &amp;#39;@&amp;#39; character followed by a file path in an argument with the file&amp;#39;s contents, allowing attackers with Overall/Read permission to read content from arbitrary files on the Jenkins controller file system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-23899</guid>
    </item>
    <item>
      <title>GHSA-vph5-2q33-7r9h — Arbitrary file read vulnerability in Git server Plugin can lead to RCE</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vph5-2q33-7r9h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.plugins:git-server&lt;/p&gt;
&lt;p&gt;Jenkins Git server Plugin uses the [args4j](https://github.com/kohsuke/args4j) library to parse command arguments and options on the Jenkins controller when processing Git commands received via SSH. This command parser has a feature that replaces an @ character followed by a file path in an argument with the file’s contents (`expandAtFiles`). This feature is enabled by default and Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable it.&lt;/p&gt;
&lt;p&gt;This allows attackers with Overall/Read permission to read the first two lines of arbitrary files on the Jenkins controller file system using the default character encoding of the Jenkins controller process.&lt;/p&gt;
&lt;p&gt;See [SECURITY-3314](https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3314) for further information about the potential impact of being able to read files on the Jenkins controller, as well as the [limitations for reading binary files](https://www.jenkins.io/security/advisory/2024-01-24/#binary-files-note). Note that for this issue, unlike SECURITY-3314, attackers need Overall/Read permission.&lt;/p&gt;
&lt;p&gt;## Fix Description
Git server Plugin 99.101.v720e86326c09 disables the command parser feature that replaces an @ character followed by a file path in an argument with the file’s contents for CLI commands.&lt;/p&gt;
&lt;p&gt;## Workaround
Navigate to Manage Jenkins » Security and ensure that the SSHD Port setting in the SSH Server section is set to Disable. This disables access to Git repositories hosted by Jenkins (and the Jenkins CLI) v…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.plugins:git-server&lt;/p&gt;
&lt;p&gt;Jenkins Git server Plugin uses the [args4j](https://github.com/kohsuke/args4j) library to parse command arguments and options on the Jenkins controller when processing Git commands received via SSH. This command parser has a feature that replaces an @ character followed by a file path in an argument with the file’s contents (`expandAtFiles`). This feature is enabled by default and Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable it.&lt;/p&gt;
&lt;p&gt;This allows attackers with Overall/Read permission to read the first two lines of arbitrary files on the Jenkins controller file system using the default character encoding of the Jenkins controller process.&lt;/p&gt;
&lt;p&gt;See [SECURITY-3314](https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3314) for further information about the potential impact of being able to read files on the Jenkins controller, as well as the [limitations for reading binary files](https://www.jenkins.io/security/advisory/2024-01-24/#binary-files-note). Note that for this issue, unlike SECURITY-3314, attackers need Overall/Read permission.&lt;/p&gt;
&lt;p&gt;## Fix Description
Git server Plugin 99.101.v720e86326c09 disables the command parser feature that replaces an @ character followed by a file path in an argument with the file’s contents for CLI commands.&lt;/p&gt;
&lt;p&gt;## Workaround
Navigate to Manage Jenkins » Security and ensure that the SSHD Port setting in the SSH Server section is set to Disable. This disables access to Git repositories hosted by Jenkins (and the Jenkins CLI) v…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vph5-2q33-7r9h</guid>
    </item>
    <item>
      <title>gsd-2024-23899</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-23899</link>
      <description>gsd-2024-23899</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-23899</guid>
    </item>
    <item>
      <title>RHSA-2024:3634 — Red Hat Security Advisory: Red Hat Product OCP Tools 4.14 OpenShift Jenkins security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:3634</link>
      <description>&lt;p&gt;ssh: Prefix truncation attack on Binary Packet Protocol (BPP) jetty: stop accepting new connections from valid clients jenkins-2-plugins: git-server plugin arbitrary file read vulnerability jenkins-2-plugins: matrix-project plugin path traversal vulnerability golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON jenkins-2-plugins: Improper input sanitization in HTML Publisher Plugin jenkins-plugin/script-security: sandbox bypass via crafted constructor bodies jenkins-plugin/script-security: sandbox bypass via sandbox-defined classes&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ssh: Prefix truncation attack on Binary Packet Protocol (BPP) jetty: stop accepting new connections from valid clients jenkins-2-plugins: git-server plugin arbitrary file read vulnerability jenkins-2-plugins: matrix-project plugin path traversal vulnerability golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON jenkins-2-plugins: Improper input sanitization in HTML Publisher Plugin jenkins-plugin/script-security: sandbox bypass via crafted constructor bodies jenkins-plugin/script-security: sandbox bypass via sandbox-defined classes&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:3634</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0199 — Jenkins: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0199</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren oder Cross-Site Scripting (XSS)-Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren oder Cross-Site Scripting (XSS)-Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0199</guid>
    </item>
  </channel>
</rss>
