Beveiligingsadvies

CVE-2023-6149

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-01-09 08:21:12
Laatst bijgewerkt 2025-06-16 19:55:06
Toegewezen door Qualys
CVSS-score 5.7
Status PUBLISHED

Beschrijving

Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity check to Qualys Cloud Services. This allowed any user with login access to configure or edit jobs to utilize the plugin and configure potential a rouge endpoint via which it was possible to control response for certain request which could be injected with XXE payloads leading to XXE while processing the response data