Required CVE Record Information
Description
Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- https://jenkins.io/security/advisory/2020-03-09/#SECURITY-1702 x_transferred
- openwall.com: [oss-security] 20200309 Multiple vulnerabilities in Jenkins plugins mailing-listx_transferred