Опубликовано: 15 янв. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5
Описание
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| lucid | DNE | |
| precise | ignored | end of life |
| precise/esm | DNE | precise was needs-triage |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | needs-triage | |
| utopic | DNE | |
| vivid | DNE |
Показывать по
10
EPSS
Процентиль: 33%
0.00132
Низкий
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
redhat
почти 11 лет назад
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query.
CVSS3: 7.5
nvd
около 6 лет назад
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query.
CVSS3: 7.5
debian
около 6 лет назад
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1. ...
CVSS3: 7.5
github
больше 3 лет назад
XML external entity (XXE) vulnerability in Jenkins
EPSS
Процентиль: 33%
0.00132
Низкий
5 Medium
CVSS2
7.5 High
CVSS3