Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat Openshift | — | Upgrade ovn2.13Upgrade openstack-ironic-inspectorUpgrade ostreeUpgrade rust-afterburnUpgrade openvswitch2.15Upgrade python-hardwareUpgrade python-jsonschemaUpgrade kata-containersUpgrade python-oslo-logUpgrade python-oslo-serializationUpgrade openshift-kuryrUpgrade python-ironic-prometheus-exporterUpgrade python-kubernetesUpgrade python-oslo-concurrencyUpgrade jenkins-2-pluginsUpgrade python-oslo-contextUpgrade python-eventletUpgrade python-oslo-configUpgrade podmanUpgrade coreos-installerUpgrade openstack-ironic-python-agentUpgrade python-ironic-libUpgrade python-openshiftUpgrade butaneUpgrade atomic-openshift-service-idlerUpgrade runcUpgrade python-sushy-oem-idracUpgrade openstack-ironicUpgrade python-oslo-i18nUpgrade python-openstacksdkUpgrade cri-toolsUpgrade python-oslo-dbUpgrade rteval-loadsUpgrade openshiftUpgrade ironic-imagesUpgrade jenkinsUpgrade python-oslo-policyUpgrade python-pyrsistentUpgrade ironic-images-ipa-x86_64Upgrade haproxyUpgrade python-keystoneauth1Upgrade redhat-release-coreosUpgrade ignitionUpgrade console-login-helper-messagesUpgrade toolboxUpgrade python-toozUpgrade python-oslo-serviceUpgrade python-stevedoreUpgrade python-oslo-utilsUpgrade openshift-ansibleUpgrade python-oslo-upgradecheckUpgrade cri-oUpgrade python-sushyUpgrade python-debtcollectorUpgrade openshift-clientsUpgrade ironic-images-ipa-ppc64le | Jun 2, 2021 | Apr 21, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub