<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 01:43:58 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-329838</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329838</link>
      <description>EUVD-2026-329838</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329838</guid>
    </item>
    <item>
      <title>fkie_cve-2026-57287</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-57287</link>
      <description>&lt;p&gt;Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations, allowing attackers with Extended Read permission to view encrypted secret values that would otherwise be redacted.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations, allowing attackers with Extended Read permission to view encrypted secret values that would otherwise be redacted.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-57287</guid>
    </item>
    <item>
      <title>GHSA-8qr4-27mh-hqfr — Jenkins Job Configuration History Plugin doesn't redact encrypted values of secrets in job and agent configurations</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8qr4-27mh-hqfr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.plugins:jobConfigHistory&lt;/p&gt;
&lt;p&gt;Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations through its &amp;#34;View as XML&amp;#34; / &amp;#34;(RAW)&amp;#34; feature and its configuration diff views.&lt;/p&gt;
&lt;p&gt;This allows attackers with Item/Extended Read permission (but not Item/Configure permission) to view the encrypted values of secrets, such as build trigger tokens, that Jenkins would otherwise redact from the configuration shown to them.&lt;/p&gt;
&lt;p&gt;Job Configuration History Plugin 1367.vc8fa_b_15101dc redacts the encrypted values of secrets when displaying historical job and agent configurations through its &amp;#34;View as XML&amp;#34; / &amp;#34;(RAW)&amp;#34; feature and its configuration diff views to users lacking Item/Configure permission.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.plugins:jobConfigHistory&lt;/p&gt;
&lt;p&gt;Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations through its &amp;#34;View as XML&amp;#34; / &amp;#34;(RAW)&amp;#34; feature and its configuration diff views.&lt;/p&gt;
&lt;p&gt;This allows attackers with Item/Extended Read permission (but not Item/Configure permission) to view the encrypted values of secrets, such as build trigger tokens, that Jenkins would otherwise redact from the configuration shown to them.&lt;/p&gt;
&lt;p&gt;Job Configuration History Plugin 1367.vc8fa_b_15101dc redacts the encrypted values of secrets when displaying historical job and agent configurations through its &amp;#34;View as XML&amp;#34; / &amp;#34;(RAW)&amp;#34; feature and its configuration diff views to users lacking Item/Configure permission.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8qr4-27mh-hqfr</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2074 — Jenkins Plugins: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2074</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Jenkins Plugins ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen und vertrauliche Informationen zu manipulieren oder offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Jenkins Plugins ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen und vertrauliche Informationen zu manipulieren oder offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2074</guid>
    </item>
  </channel>
</rss>
