Description
Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1376 | Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
Github GHSA |
GHSA-qgm7-m77f-j8pf | Jenkins Performance Publisher Plugin vulnerable to XML external entity (XXE) attacks |
References
History
Tue, 25 Feb 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-02-25T18:58:07.351Z
Reserved: 2023-03-20T19:59:08.758Z
Link: CVE-2023-28682
Updated: 2024-08-02T13:43:23.672Z
Status : Modified
Published: 2023-04-02T21:15:09.367
Modified: 2025-02-25T19:15:14.060
Link: CVE-2023-28682
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA