XML External Entities Vulnerability in Jenkins Token Macro Plugin
CVE-2019-10337

7.5HIGH

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
11 June 2019

Summary

An XML external entities (XXE) vulnerability exists in Jenkins Token Macro Plugin versions 2.7 and earlier. This issue allows remote attackers to manipulate the input file for the 'XML' macro to resolve external entities. The exploitation of this vulnerability can lead to the unauthorized extraction of sensitive data from the Jenkins agent, enabling server-side request forgery and potential denial-of-service attacks.

Affected Version(s)

Jenkins Token Macro Plugin 2.7 and earlier

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.