PT-2024-1590 · Qualys · Qualys Jenkins Plugin For Policy Compliance

Published

2024-01-09

·

Updated

2024-01-24

·

CVE-2023-6147

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Qualys Jenkins Plugin for Policy Compliance versions prior to 1.0.6
Description The issue is related to the Qualys Policy Compliance Connector Plugin and involves incorrect restriction of XML links to external objects, allowing a remote attacker to conduct XXE attacks using specially crafted XML code. The vulnerability is due to a missing permission check while performing a connectivity check to Qualys Cloud Services, enabling any user with login access to configure or edit jobs to utilize the plugin and potentially control responses for certain requests, which could be injected with XXE payloads.
Recommendations For Qualys Jenkins Plugin for Policy Compliance versions prior to 1.0.6, update to version 1.0.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin to minimize the risk of exploitation.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01178
CVE-2023-6147
GHSA-8525-52VG-JV6V

Affected Products

Qualys Jenkins Plugin For Policy Compliance