Description
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2507 | Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
Github GHSA |
GHSA-ghjw-fcf6-rpr9 | Job Configuration History Plugin's path traversal allows exploiting XXE vulnerability |
References
History
Fri, 27 Sep 2024 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-09-26T19:57:44.018Z
Reserved: 2023-09-05T16:39:57.391Z
Link: CVE-2023-41933
Updated: 2024-08-02T19:09:49.240Z
Status : Modified
Published: 2023-09-06T13:15:10.000
Modified: 2024-11-21T08:21:56.923
Link: CVE-2023-41933
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA