Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 27 Sep 2024 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2024-09-26T19:57:44.018Z

Reserved: 2023-09-05T16:39:57.391Z

Link: CVE-2023-41933

cve-icon Vulnrichment

Updated: 2024-08-02T19:09:49.240Z

cve-icon NVD

Status : Modified

Published: 2023-09-06T13:15:10.000

Modified: 2024-11-21T08:21:56.923

Link: CVE-2023-41933

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.