XML External Entity Vulnerability in Jenkins NUnit Plugin
CVE-2020-2115

8.8HIGH

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
12 February 2020

What is CVE-2020-2115?

The Jenkins NUnit Plugin versions up to and including 0.25 are subject to an XML External Entity (XXE) vulnerability due to improper configuration of the XML parser. This flaw can be exploited by an attacker to gain access to sensitive data on the server or potentially execute external requests. Users are advised to upgrade to the latest version of the plugin to mitigate the risk and ensure the security of their Jenkins environment.

Affected Version(s)

Jenkins NUnit Plugin <= 0.25

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.