Description
Jenkins Phabricator Differential Plugin 2.1.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1401 | Jenkins Phabricator Differential Plugin 2.1.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
Github GHSA |
GHSA-w4g6-8xqp-g92m | Jenkins Phabricator Differential Plugin vulnerable to XML external entity (XXE) attacks |
References
History
Fri, 21 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-02-21T15:51:18.858Z
Reserved: 2023-03-20T19:59:08.758Z
Link: CVE-2023-28683
Updated: 2024-08-02T13:43:23.670Z
Status : Modified
Published: 2023-04-02T21:15:09.407
Modified: 2025-02-21T16:15:31.807
Link: CVE-2023-28683
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA