Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1238 | Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
Github GHSA |
GHSA-8j88-2hfc-5rf3 | Jenkins Visual Studio Code Metrics Plugin vulnerable to XML external entity (XXE) attacks |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Feb 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-02-25T19:08:45.289Z
Reserved: 2023-03-20T19:59:08.758Z
Link: CVE-2023-28681
Updated: 2024-08-02T13:43:23.644Z
Status : Modified
Published: 2023-04-02T21:15:09.323
Modified: 2025-02-25T19:15:13.900
Link: CVE-2023-28681
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA