Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-882r-r8fw-p538

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

XXE vulnerability in Jenkins Job Import Plugin

An XML external entity (XXE) processing vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport/client/RestApiClient.java that allows attackers with the ability to control the HTTP server (Jenkins) queried in preparation of job import to read arbitrary files, perform a denial of service attack, etc.

Пакеты

Наименование

org.jenkins-ci.plugins:job-import-plugin

maven
Затронутые версииВерсия исправления

< 3.0

3.0

EPSS

Процентиль: 30%
0.0011
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 9.1
nvd
около 7 лет назад

An XML external entity processing vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport/client/RestApiClient.java that allows attackers with the ability to control the HTTP server (Jenkins) queried in preparation of job import to read arbitrary files, perform a denial of service attack, etc.

EPSS

Процентиль: 30%
0.0011
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-611