PT-2021-14700 · Jenkins · Jenkins Filesystem Trigger Plugin+1

Kevin Guerroudj

·

Published

2021-05-25

·

Updated

2023-10-25

·

CVE-2021-21657

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Filesystem Trigger Plugin versions 0.40 and earlier
Description The issue allows attackers with Job/Configure permission or those able to control the contents of an XML file being polled for changes to have Jenkins parse a crafted XML document. This can lead to extraction of secrets from the polling Jenkins controller or agent, server-side request forgery, or denial-of-service attacks. The problem arises because the XML parser is not configured to prevent XML external entity (XXE) attacks.
Recommendations For Jenkins Filesystem Trigger Plugin versions 0.40 and earlier, update to version 0.41 or later, which disables external entity resolution for its XML parser.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2021-21657
GHSA-CPHV-7CXW-5HCC

Affected Products

Jenkins
Jenkins Filesystem Trigger Plugin