Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Job/Configure permissions.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-3699 Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Job/Configure permissions.
Github GHSA Github GHSA GHSA-f5wx-w2f9-82gh XXE vulnerability in Jenkins WebSphere Deployer Plugin
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2024-08-04T07:01:39.769Z

Reserved: 2019-12-05T00:00:00

Link: CVE-2020-2108

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-01-29T16:15:12.787

Modified: 2024-11-21T05:24:39.547

Link: CVE-2020-2108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses