<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 07:56:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-265586</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-265586</link>
      <description>EUVD-2026-265586</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-265586</guid>
    </item>
    <item>
      <title>fkie_cve-2025-68703</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68703</link>
      <description>&lt;p&gt;Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived from sha256Sum(passphrase). Two encryption operations with the same password will have the same derived key. This vulnerability is fixed in 2.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived from sha256Sum(passphrase). Two encryption operations with the same password will have the same derived key. This vulnerability is fixed in 2.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-68703</guid>
    </item>
    <item>
      <title>GHSA-36h5-vrq6-pp34 — Jervis's Salt for PBKDF2 derived from password</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-36h5-vrq6-pp34</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: net.gleske:jervis&lt;/p&gt;
&lt;p&gt;### Vulnerability&lt;/p&gt;
&lt;p&gt;https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L869-L870&lt;/p&gt;
&lt;p&gt;https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L894-L895&lt;/p&gt;
&lt;p&gt;The salt is derived from sha256Sum(passphrase).  Two encryption operations with the same password will have the same derived key.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Pre-computation attacks.&lt;/p&gt;
&lt;p&gt;Severity is considered low for internal uses of this library and high for consumers of this library.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Jervis will generate a random salt for each password and store it alongside the ciphertext.&lt;/p&gt;
&lt;p&gt;Upgrade to Jervis 2.2.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- [NIST SP 800-132: Password-Based Key Derivation](https://csrc.nist.gov/publications/detail/sp/800-132/final)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: net.gleske:jervis&lt;/p&gt;
&lt;p&gt;### Vulnerability&lt;/p&gt;
&lt;p&gt;https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L869-L870&lt;/p&gt;
&lt;p&gt;https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L894-L895&lt;/p&gt;
&lt;p&gt;The salt is derived from sha256Sum(passphrase).  Two encryption operations with the same password will have the same derived key.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Pre-computation attacks.&lt;/p&gt;
&lt;p&gt;Severity is considered low for internal uses of this library and high for consumers of this library.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Jervis will generate a random salt for each password and store it alongside the ciphertext.&lt;/p&gt;
&lt;p&gt;Upgrade to Jervis 2.2.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- [NIST SP 800-132: Password-Based Key Derivation](https://csrc.nist.gov/publications/detail/sp/800-132/final)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-36h5-vrq6-pp34</guid>
    </item>
  </channel>
</rss>
