PT-2020-15513 · Jenkins · Jenkins Liquibase Runner Plugin+1

Daniel Beck

·

Published

2020-09-23

·

Updated

2023-10-25

·

CVE-2020-2284

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Liquibase Runner Plugin versions 1.4.5 and earlier
Description The issue allows attackers to provide crafted XML files that use external entities for extraction of secrets from the Jenkins controller or server-side request forgery. This is possible because the plugin does not configure its XML parser to prevent XML external entity (XXE) attacks, enabling attackers to have Jenkins parse malicious XML files when evaluating Liquibase changesets.
Recommendations For Jenkins Liquibase Runner Plugin versions 1.4.5 and earlier, update to version 1.4.7 or later, which no longer parses Liquibase changesets, thereby mitigating the risk of XXE attacks.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2020-2284
GHSA-XX7G-F287-F9FQ

Affected Products

Jenkins
Jenkins Liquibase Runner Plugin