XML External Entity Vulnerability in Jenkins Robot Framework Plugin
CVE-2020-2092

8.8HIGH

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
15 January 2020

What is CVE-2020-2092?

The Jenkins Robot Framework Plugin, prior to version 2.0.0, is susceptible to XML External Entity (XXE) attacks. This vulnerability arises from the plugin's failure to appropriately configure its XML parser, which allows unauthorized users with Job/Configure permissions to craft and submit malicious XML documents. If exploited, this vulnerability can lead to potential data exfiltration and system compromise, making it imperative for users to upgrade to the latest version to mitigate risk.

Affected Version(s)

Jenkins Robot Framework Plugin <= 2.0.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.