<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 21:50:21 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-265589</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-265589</link>
      <description>EUVD-2026-265589</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-265589</guid>
    </item>
    <item>
      <title>fkie_cve-2025-68931</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68931</link>
      <description>&lt;p&gt;Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding lacks authentication, making it vulnerable to padding oracle attacks and ciphertext manipulation. This vulnerability is fixed in 2.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding lacks authentication, making it vulnerable to padding oracle attacks and ciphertext manipulation. This vulnerability is fixed in 2.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-68931</guid>
    </item>
    <item>
      <title>GHSA-gxp5-mv27-vjcj — Jervis's AES CBC Mode is Without Authentication</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gxp5-mv27-vjcj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: net.gleske:jervis&lt;/p&gt;
&lt;p&gt;### Vulnerability&lt;/p&gt;
&lt;p&gt;https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L682-L684&lt;/p&gt;
&lt;p&gt;https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L720-L722&lt;/p&gt;
&lt;p&gt;`AES/CBC/PKCS5Padding` lacks authentication, making it vulnerable to padding oracle attacks and ciphertext manipulation.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Severity is considered low for internal uses of this library but if there&amp;#39;s any consumer using these methods directly then this is considered critical.&lt;/p&gt;
&lt;p&gt;Unlikely to matter due to the design of how AES-256-CBC is used in conjunction with RSA and SHA-256 checksum within Jervis.&lt;/p&gt;
&lt;p&gt;Jervis uses RSA to encrypt AES keys and a SHA-256 checksum of the encrypted data in local-only storage inaccessible from the web.  After asymmetric decryption and before symmetric decryption, a SHA-256 checksum is performed on the metadata and encrypted data. All encrypted data is discarded if the checksum does not match without attempting to decrypt since the encrypted data is assumed invalid.  The data stored is GitHub App authentication tokens which will expire within one hour.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Jervis patch will migrate from `AES/CBC/PKCS5Padding` to `AES/GCM/NoPadding`.&lt;/p&gt;
&lt;p&gt;Upgrade to Jervis 2.2.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- [Padding Oracle Attacks](https://en.wikipedia.org/wiki/Padding_oracle_attack)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: net.gleske:jervis&lt;/p&gt;
&lt;p&gt;### Vulnerability&lt;/p&gt;
&lt;p&gt;https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L682-L684&lt;/p&gt;
&lt;p&gt;https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L720-L722&lt;/p&gt;
&lt;p&gt;`AES/CBC/PKCS5Padding` lacks authentication, making it vulnerable to padding oracle attacks and ciphertext manipulation.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Severity is considered low for internal uses of this library but if there&amp;#39;s any consumer using these methods directly then this is considered critical.&lt;/p&gt;
&lt;p&gt;Unlikely to matter due to the design of how AES-256-CBC is used in conjunction with RSA and SHA-256 checksum within Jervis.&lt;/p&gt;
&lt;p&gt;Jervis uses RSA to encrypt AES keys and a SHA-256 checksum of the encrypted data in local-only storage inaccessible from the web.  After asymmetric decryption and before symmetric decryption, a SHA-256 checksum is performed on the metadata and encrypted data. All encrypted data is discarded if the checksum does not match without attempting to decrypt since the encrypted data is assumed invalid.  The data stored is GitHub App authentication tokens which will expire within one hour.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Jervis patch will migrate from `AES/CBC/PKCS5Padding` to `AES/GCM/NoPadding`.&lt;/p&gt;
&lt;p&gt;Upgrade to Jervis 2.2.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- [Padding Oracle Attacks](https://en.wikipedia.org/wiki/Padding_oracle_attack)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gxp5-mv27-vjcj</guid>
    </item>
  </channel>
</rss>
