XML External Entity Vulnerability in Jenkins NUnit Plugin
CVE-2020-2115
8.8HIGH
Summary
The Jenkins NUnit Plugin versions up to and including 0.25 are subject to an XML External Entity (XXE) vulnerability due to improper configuration of the XML parser. This flaw can be exploited by an attacker to gain access to sensitive data on the server or potentially execute external requests. Users are advised to upgrade to the latest version of the plugin to mitigate the risk and ensure the security of their Jenkins environment.
Affected Version(s)
Jenkins NUnit Plugin <= 0.25
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved