VulnerabilityModified
CVE-2021-21642
Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
HIGH 8.1EPSS 37.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 37.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 37.83% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- jenkins/config file provider
- Source
- jenkinsci-cert@googlegroups.com
References
- http://www.openwall.com/lists/oss-security/2021/04/21/2Mailing List, Third Party Advisory
- https://www.jenkins.io/security/advisory/2021-04-21/#SECURITY-2204Vendor Advisory
- http://www.openwall.com/lists/oss-security/2021/04/21/2Mailing List, Third Party Advisory
- https://www.jenkins.io/security/advisory/2021-04-21/#SECURITY-2204Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.