PT-2024-1590 · Qualys · Qualys Jenkins Plugin For Policy Compliance
Published
2024-01-09
·
Updated
2024-01-24
·
CVE-2023-6147
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Qualys Jenkins Plugin for Policy Compliance versions prior to 1.0.6
Description
The issue is related to the Qualys Policy Compliance Connector Plugin and involves incorrect restriction of XML links to external objects, allowing a remote attacker to conduct XXE attacks using specially crafted XML code. The vulnerability is due to a missing permission check while performing a connectivity check to Qualys Cloud Services, enabling any user with login access to configure or edit jobs to utilize the plugin and potentially control responses for certain requests, which could be injected with XXE payloads.
Recommendations
For Qualys Jenkins Plugin for Policy Compliance versions prior to 1.0.6, update to version 1.0.6 or later to resolve the issue.
As a temporary workaround, consider restricting access to the plugin to minimize the risk of exploitation.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qualys Jenkins Plugin For Policy Compliance