XML External Entities Vulnerability in Jenkins Token Macro Plugin
CVE-2019-10337
7.5HIGH
Summary
An XML external entities (XXE) vulnerability exists in Jenkins Token Macro Plugin versions 2.7 and earlier. This issue allows remote attackers to manipulate the input file for the 'XML' macro to resolve external entities. The exploitation of this vulnerability can lead to the unauthorized extraction of sensitive data from the Jenkins agent, enabling server-side request forgery and potential denial-of-service attacks.
Affected Version(s)
Jenkins Token Macro Plugin 2.7 and earlier
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved