XML External Entity Processing Vulnerability in Jenkins Self-Organizing Swarm Plug-in Modules
CVE-2019-10309
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 30 April 2019
What is CVE-2019-10309?
The Jenkins Self-Organizing Swarm Plug-in Modules contains a vulnerability that allows clients leveraging UDP broadcasts for discovering Jenkins masters to process XML External Entities. This flaw enables unauthorized attackers on the same network to read arbitrary files from Swarm clients, potentially leading to data exposure and confidentiality breaches. Addressing this vulnerability is crucial for maintaining the security of Jenkins installations and protecting sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.15 and earlier
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved