vulnerability
Red Hat OpenShift: CVE-2019-10337: jenkins-plugin-token-macro: XML External Entity processing the ${XML} macro
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
5 | (AV:N/AC:L/Au:N/C:N/I:N/A:P) | Jun 11, 2019 | Jul 4, 2019 | Nov 27, 2024 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Jun 11, 2019
Added
Jul 4, 2019
Modified
Nov 27, 2024
Description
An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks.
Solution(s)
linuxrpm-upgrade-atomic-openshiftlinuxrpm-upgrade-jenkins-2-plugins

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.