Описание
XXE vulnerability in Jenkins Klocwork Analysis Plugin
Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
This allows a user able to control the input files for the Klocwork plugin parser to have Jenkins parse a crafted file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.
Пакеты
Наименование
org.jenkins-ci.plugins:klocwork
maven
Затронутые версииВерсия исправления
<= 2020.2.1
2020.3.1
Связанные уязвимости
CVSS3: 6.5
nvd
больше 5 лет назад
Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.