<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 14:15:54 +0000</lastBuildDate>
    <item>
      <title>cnvd-2016-03162</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2016-03162</link>
      <description>cnvd-2016-03162</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2016-03162</guid>
    </item>
    <item>
      <title>EUVD-2026-83784</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-83784</link>
      <description>EUVD-2026-83784</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-83784</guid>
    </item>
    <item>
      <title>fkie_cve-2016-3727</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2016-3727</link>
      <description>&lt;p&gt;The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2016-3727</guid>
    </item>
    <item>
      <title>GHSA-6cr3-cm5h-8q96 — Jenkins Exposes Sensitive Information via API URL</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6cr3-cm5h-8q96</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.main:jenkins-core&lt;/p&gt;
&lt;p&gt;The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.main:jenkins-core&lt;/p&gt;
&lt;p&gt;The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6cr3-cm5h-8q96</guid>
    </item>
    <item>
      <title>gsd-2016-3727</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2016-3727</link>
      <description>gsd-2016-3727</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2016-3727</guid>
    </item>
    <item>
      <title>RHSA-2016:1206 — Red Hat Security Advisory: jenkins security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2016:1206</link>
      <description>&lt;p&gt;jenkins: Arbitrary build parameters are passed to build scripts as environment variables (SECURITY-170) jenkins: Malicious users with multiple user accounts can prevent other users from logging in (SECURITY-243) jenkins: Information on installed plugins exposed via API (SECURITY-250) jenkins: Encrypted secrets (e.g. passwords) were leaked to users with permission to read configuration (SECURITY-266) jenkins: Regular users can trigger download of update site metadata (SECURITY-273) jenkins: Open redirect to scheme-relative URLs (SECURITY-276) jenkins: Granting the permission to read node configurations allows access to overall system configuration (SECURITY-281)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jenkins: Arbitrary build parameters are passed to build scripts as environment variables (SECURITY-170) jenkins: Malicious users with multiple user accounts can prevent other users from logging in (SECURITY-243) jenkins: Information on installed plugins exposed via API (SECURITY-250) jenkins: Encrypted secrets (e.g. passwords) were leaked to users with permission to read configuration (SECURITY-266) jenkins: Regular users can trigger download of update site metadata (SECURITY-273) jenkins: Open redirect to scheme-relative URLs (SECURITY-276) jenkins: Granting the permission to read node configurations allows access to overall system configuration (SECURITY-281)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2016:1206</guid>
    </item>
  </channel>
</rss>
