SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-43576

Jenkins pom2config Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers with Overall/Read and Item/Read permissions to have Jenkins parse a crafted XML file that uses external entities…

MEDIUM 6.5EPSS 2.44%

Does this matter?

Lower severity and a low EPSS score (2.44%). Track it; it rarely justifies an emergency change on its own.

Description

Jenkins pom2config Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers with Overall/Read and Item/Read permissions to have Jenkins parse a crafted XML file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
2.44% probability · 83th percentile
CISA KEV
Not listed
Weakness
CWE-611
Affected
jenkins/pom2config
Source
jenkinsci-cert@googlegroups.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.