Security Advisory

CVE-2021-43576

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-11-12 10:35:20
Last updated 2024-08-04 04:03:08
Assigner jenkins
CVSS score not scored
State PUBLISHED

Description

Jenkins pom2config Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers with Overall/Read and Item/Read permissions to have Jenkins parse a crafted XML file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.