PT-2020-7808 · Jenkins · Jenkins

Daniel Beck

·

Published

2020-01-15

·

Updated

2022-05-24

·

CVE-2015-1811

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Jenkins versions prior to 1.600 Jenkins LTS versions prior to 1.596.1
Description: The issue allows remote attackers to read arbitrary XML files via a crafted XML document, exploiting an XML external entity (XXE) vulnerability. This enables attackers to access sensitive data by manipulating XML documents.
Recommendations: For Jenkins versions prior to 1.600, update to version 1.600 or later. For Jenkins LTS versions prior to 1.596.1, update to version 1.596.1 or later.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-1811
GHSA-QG7X-4H4Q-3M49
RHSA-2015:1844

Affected Products

Jenkins