Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6755-jgp4-8q7h

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

XML External Entity processing vulnerability in Pipeline Maven Integration Jenkins Plugin

An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed attackers able to control a temporary directory's content on the agent running the Maven build to have Jenkins parse a maliciously crafted XML file that uses external entities for extraction of secrets from the Jenkins master, server-side request forgery, or denial-of-service attacks.

Пакеты

Наименование

org.jenkins-ci.plugins:pipeline-maven

maven
Затронутые версииВерсия исправления

< 3.7.1

3.7.1

EPSS

Процентиль: 36%
0.00148
Низкий

8.1 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 8.1
nvd
больше 6 лет назад

An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed attackers able to control a temporary directory's content on the agent running the Maven build to have Jenkins parse a maliciously crafted XML file that uses external entities for extraction of secrets from the Jenkins master, server-side request forgery, or denial-of-service attacks.

EPSS

Процентиль: 36%
0.00148
Низкий

8.1 High

CVSS3

Дефекты

CWE-611