vulnerability

Red Hat OpenShift: CVE-2019-10337: jenkins-plugin-token-macro: XML External Entity processing the ${XML} macro

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Jun 11, 2019
Added
Jul 4, 2019
Modified
Nov 27, 2024

Description

An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks.

Solution(s)

linuxrpm-upgrade-atomic-openshiftlinuxrpm-upgrade-jenkins-2-plugins
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.