XML External Entity Vulnerability in Jenkins Performance Publisher Plugin
CVE-2023-28682
8.2HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 2 April 2023
What is CVE-2023-28682?
The Jenkins Performance Publisher Plugin versions 8.09 and earlier are susceptible to XML External Entity (XXE) attacks. This vulnerability arises from improper configuration of the XML parser, which can allow attackers to interfere with the processing of XML input. Consequently, malicious entities could potentially leverage this flaw to access sensitive information, facilitate system interactions, or execute arbitrary commands, posing significant risks to the integrity and confidentiality of the data managed by Jenkins.
Affected Version(s)
Jenkins Performance Publisher Plugin 0 <= 8.09