Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wcrg-92wp-4h28

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

XXE vulnerability in Jenkins Nerrvana Plugin

Jenkins Nerrvana Plugin 1.02.06 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

This allows attackers with Overall/Read permission to have Jenkins parse a crafted HTTP request with XML data that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.

Additionally, XML parsing is exposed as a form validation endpoint that does not require POST requests, allowing exploitation by users without Overall/Read permission via CSRF.

Пакеты

Наименование

org.jenkins-ci.plugins:nerrvana-plugin

maven
Затронутые версииВерсия исправления

<= 1.02.06

Отсутствует

EPSS

Процентиль: 71%
0.00686
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 6.5
nvd
больше 5 лет назад

Jenkins Nerrvana Plugin 1.02.06 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

EPSS

Процентиль: 71%
0.00686
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-611