<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 21:07:39 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-260077</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-260077</link>
      <description>EUVD-2026-260077</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-260077</guid>
    </item>
    <item>
      <title>fkie_cve-2025-64132</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64132</link>
      <description>&lt;p&gt;Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger builds and obtain information about job and cloud configuration they should not be able to access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger builds and obtain information about job and cloud configuration they should not be able to access.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-64132</guid>
    </item>
    <item>
      <title>GHSA-mrpq-9jr3-rqq9 — Jenkins MCP Server Plugin does not perform permission checks in multiple MCP tools</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mrpq-9jr3-rqq9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.jenkins.plugins:mcp-server&lt;/p&gt;
&lt;p&gt;Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in several MCP tools.&lt;/p&gt;
&lt;p&gt;This allows to do the following:&lt;/p&gt;
&lt;p&gt;- Attackers with Item/Read permission can obtain information about the configured SCM in a job despite lacking Item/Extended Read permission (`getJobScm`).&lt;/p&gt;
&lt;p&gt;- Attackers with Item/Read permission can trigger new builds of a job despite lacking Item/Build permission (`triggerBuild`).&lt;/p&gt;
&lt;p&gt;- Attackers without Overall/Read permission can retrieve the names of configured clouds (`getStatus`).&lt;/p&gt;
&lt;p&gt;MCP Server Plugin 0.86.v7d3355e6a_a_18 performs permission checks for the affected MCP tools.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.jenkins.plugins:mcp-server&lt;/p&gt;
&lt;p&gt;Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in several MCP tools.&lt;/p&gt;
&lt;p&gt;This allows to do the following:&lt;/p&gt;
&lt;p&gt;- Attackers with Item/Read permission can obtain information about the configured SCM in a job despite lacking Item/Extended Read permission (`getJobScm`).&lt;/p&gt;
&lt;p&gt;- Attackers with Item/Read permission can trigger new builds of a job despite lacking Item/Build permission (`triggerBuild`).&lt;/p&gt;
&lt;p&gt;- Attackers without Overall/Read permission can retrieve the names of configured clouds (`getStatus`).&lt;/p&gt;
&lt;p&gt;MCP Server Plugin 0.86.v7d3355e6a_a_18 performs permission checks for the affected MCP tools.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mrpq-9jr3-rqq9</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2443 — Jenkins Plugins: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2443</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen und serverseitige Request-Forgery durchzuführen&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen und serverseitige Request-Forgery durchzuführen&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2443</guid>
    </item>
  </channel>
</rss>
