PT-2020-15466 · Jenkins · Jenkins Valgrind Plugin+1

Federico Pellegrin

·

Published

2020-09-01

·

Updated

2023-10-25

·

CVE-2020-2245

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Valgrind Plugin versions 0.28 and earlier
Description The issue concerns the configuration of the XML parser in the Jenkins Valgrind Plugin, which does not prevent XML external entity (XXE) attacks. This allows a user who can control the input files for the Valgrind plugin parser to have Jenkins parse a crafted file that uses external entities. This can lead to the extraction of secrets from the Jenkins controller or server-side request forgery.
Recommendations For Jenkins Valgrind Plugin versions 0.28 and earlier, consider disabling the XML parser or restricting the input files for the Valgrind plugin parser until a patch is available. As a temporary workaround, restrict access to the plugin's configuration to minimize the risk of exploitation.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-2245
GHSA-XQ2Q-8HXC-7JR2

Affected Products

Jenkins
Jenkins Valgrind Plugin