Vulnerability GHSA-ghjw-fcf6-rpr9

High Risk
HIGH RISK
CVSS Score: 8.8
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 years ago
September 06, 2023 at 03:30 PM UTC
Job Configuration History Plugin's path traversal allows exploiting XXE vulnerability
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0

Summary

Job Configuration History Plugin's path traversal allows exploiting XXE vulnerability

Details

Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Timeline

Published
3 years ago
September 06, 2023 at 03:30 PM UTC
Last Modified
2 years ago
February 16, 2024 at 08:20 AM UTC