Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-687x-269m-7cv9

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

XXE vulnerability in Jenkins PMD Plugin

Jenkins PMD Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.

Пакеты

Наименование

org.jvnet.hudson.plugins:pmd

maven
Затронутые версииВерсия исправления

<= 3.49

3.50

EPSS

Процентиль: 22%
0.00074
Низкий

8.8 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 8.8
nvd
около 8 лет назад

Jenkins PMD Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.

EPSS

Процентиль: 22%
0.00074
Низкий

8.8 High

CVSS3

Дефекты

CWE-611