Описание
Jenkins 360 FireLine Plugin vulnerable to XML External Entity Reference
An XML external entities (XXE) vulnerability in Jenkins 360 FireLine Plugin allows attackers with Overall/Read access to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks.
Note: Jenkins has suspended distribution of this plugin.
Пакеты
Наименование
org.jenkins-ci.plugins.plugin:fireline
maven
Затронутые версииВерсия исправления
<= 1.7.2
Отсутствует
Связанные уязвимости
CVSS3: 8.1
nvd
больше 6 лет назад
An XML external entities (XXE) vulnerability in Jenkins 360 FireLine Plugin allows attackers with Overall/Read access to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks.