XML External Entity Flaw in Jenkins 360 FireLine Plugin
CVE-2019-10466
What is CVE-2019-10466?
The Jenkins 360 FireLine Plugin is susceptible to an XML External Entity (XXE) vulnerability, which enables attackers with Overall/Read access to manipulate the XML parser. This flaw can lead to the disclosure of sensitive information by allowing attackers to resolve external entities. Consequently, this can result in the extraction of secrets from the Jenkins agent, server-side request forgery, or potential denial-of-service attacks, significantly undermining the security posture of the affected Jenkins installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins 360 FireLine Plugin 1.7.2 and earlier
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved