Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8rx6-v5q4-xw3j

Опубликовано: 30 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

enkins Coverage/Complexity Scatter Plot Plugin XML External Entity Reference vulnerability

Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

This allows attackers able to control the input files for the 'Public Coverage / Complexity Scatter Plot' post-build step to have Jenkins parse a crafted file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.

As of publication of this advisory, there is no fix.

Пакеты

Наименование

org.jenkins-ci.plugins:covcomplplot

maven
Затронутые версииВерсия исправления

<= 1.1.1

Отсутствует

EPSS

Процентиль: 92%
0.0747
Низкий

7.1 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 8.1
nvd
почти 4 года назад

Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

EPSS

Процентиль: 92%
0.0747
Низкий

7.1 High

CVSS3

Дефекты

CWE-611