CVE-2021-43576
Jenkins pom2config Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers with Overall/Read and Item/Read permissions to have Jenkins parse a crafted XML file that uses external entities…
Does this matter?
Lower severity and a low EPSS score (2.44%). Track it; it rarely justifies an emergency change on its own.
Description
Jenkins pom2config Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers with Overall/Read and Item/Read permissions to have Jenkins parse a crafted XML file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 2.44% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- jenkins/pom2config
- Source
- jenkinsci-cert@googlegroups.com
References
- http://www.openwall.com/lists/oss-security/2021/11/12/1Mailing List, Third Party Advisory
- https://www.jenkins.io/security/advisory/2021-11-12/#SECURITY-2415Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-1314/Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2021/11/12/1Mailing List, Third Party Advisory
- https://www.jenkins.io/security/advisory/2021-11-12/#SECURITY-2415Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-1314/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.