Description
Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0324 | Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
Github GHSA |
GHSA-3ppr-72x5-x67q | XML external entity vulnerability on agents in Jenkins MSTest Plugin |
References
History
Thu, 03 Apr 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-04-02T13:54:26.461Z
Reserved: 2023-01-23T00:00:00.000Z
Link: CVE-2023-24441
Updated: 2024-08-02T10:56:04.104Z
Status : Modified
Published: 2023-01-26T21:18:17.907
Modified: 2025-04-02T14:15:39.470
Link: CVE-2023-24441
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA