XML External Entity Flaw in Jenkins 360 FireLine Plugin
CVE-2019-10466

8.1HIGH

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
23 October 2019

Summary

The Jenkins 360 FireLine Plugin is susceptible to an XML External Entity (XXE) vulnerability, which enables attackers with Overall/Read access to manipulate the XML parser. This flaw can lead to the disclosure of sensitive information by allowing attackers to resolve external entities. Consequently, this can result in the extraction of secrets from the Jenkins agent, server-side request forgery, or potential denial-of-service attacks, significantly undermining the security posture of the affected Jenkins installations.

Affected Version(s)

Jenkins 360 FireLine Plugin 1.7.2 and earlier

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.