Description
Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read arbitrary files from Swarm clients.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5531 | Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read arbitrary files from Swarm clients. |
Github GHSA |
GHSA-w898-3ph8-5pgm | Jenkins Self-Organizing Swarm Plug-in Modules Plugin XXE vulnerability via UDP broadcast response |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-04T22:17:20.298Z
Reserved: 2019-03-29T00:00:00.000Z
Link: CVE-2019-10309
No data.
Status : Modified
Published: 2019-04-30T13:29:05.407
Modified: 2024-11-21T04:18:51.743
Link: CVE-2019-10309
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA