CVE-2019-10309
Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.79%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read arbitrary files from Swarm clients.
- CVSS 3.0
- 9.3 CRITICALCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
- EPSS
- 1.79% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- jenkins/self-organizing swarm modules
- Source
- jenkinsci-cert@googlegroups.com
References
- http://www.openwall.com/lists/oss-security/2019/04/30/5Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/108159
- https://jenkins.io/security/advisory/2019-04-30/#SECURITY-1252Vendor Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0783
- http://www.openwall.com/lists/oss-security/2019/04/30/5Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/108159
- https://jenkins.io/security/advisory/2019-04-30/#SECURITY-1252Vendor Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0783
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.