PT-2020-15549 · Jenkins · Jenkins Visualworks Store Plugin+1

Jeff Thompson

·

Published

2020-11-04

·

Updated

2023-10-25

·

CVE-2020-2315

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Visualworks Store Plugin versions 1.1.3 and earlier
Description The issue allows attackers with the ability to control the output of a script that runs Visualworks with StoreCI, or able to control an agent process, to have Jenkins parse a crafted file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery. This is due to the plugin not configuring its XML parser to prevent XML external entity (XXE) attacks.
Recommendations For Jenkins Visualworks Store Plugin versions 1.1.3 and earlier, update to version 1.1.4 or later, which disables external entity resolution for its XML parser.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2020-2315
GHSA-JVJM-J945-8QWC

Affected Products

Jenkins
Jenkins Visualworks Store Plugin