PT-2022-25757 · Jenkins · Jenkins Rqm Plugin+1

Kevin Guerroudj

·

Published

2022-09-21

·

Updated

2025-05-28

·

CVE-2022-41241

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins RQM Plugin versions 2.8 and earlier
Description The issue is related to the XML parser not being configured to prevent XML external entity (XXE) attacks. This allows attackers to provide crafted API responses that can be used to extract secrets from the Jenkins controller or perform server-side request forgery by having Jenkins parse a crafted XML document that uses external entities.
Recommendations For Jenkins RQM Plugin versions 2.8 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Weakness Enumeration

Related Identifiers

CVE-2022-41241
GHSA-J8XR-2279-88QJ

Affected Products

Jenkins
Jenkins Rqm Plugin