XML External Entity Vulnerability in Jenkins Subversion Plugin
CVE-2020-2304
6.5MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 4 November 2020
What is CVE-2020-2304?
The Jenkins Subversion Plugin versions 2.13.1 and earlier are vulnerable to XML External Entity (XXE) attacks due to improper configuration of the XML parser. Due to this vulnerability, attackers can leverage specially crafted XML documents to extract sensitive data, access internal resources, or potentially execute server-side requests. It is crucial to update to the latest version of the plugin to mitigate these security risks and safeguard your Jenkins environment.
Affected Version(s)
Jenkins Subversion Plugin <= 2.13.1