Description
Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0484 | Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
Github GHSA |
GHSA-h8p8-6378-649p | XML external entity reference vulnerability on agents in Jenkins Semantic Versioning Plugin |
References
History
Wed, 02 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-04-02T14:21:38.174Z
Reserved: 2023-01-23T00:00:00.000Z
Link: CVE-2023-24430
Updated: 2024-08-02T10:56:04.218Z
Status : Modified
Published: 2023-01-26T21:18:17.170
Modified: 2025-04-02T15:15:55.567
Link: CVE-2023-24430
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA