XML External Entity Flaw in Jenkins 360 FireLine Plugin
CVE-2019-10466
8.1HIGH
What is CVE-2019-10466?
The Jenkins 360 FireLine Plugin is susceptible to an XML External Entity (XXE) vulnerability, which enables attackers with Overall/Read access to manipulate the XML parser. This flaw can lead to the disclosure of sensitive information by allowing attackers to resolve external entities. Consequently, this can result in the extraction of secrets from the Jenkins agent, server-side request forgery, or potential denial-of-service attacks, significantly undermining the security posture of the affected Jenkins installations.
Affected Version(s)
Jenkins 360 FireLine Plugin 1.7.2 and earlier