CVE-2015-1809: XEE
This vulnerability allows users with the read access to Jenkins to retrieve arbitrary XML document on the server, resulting in the exposure of sensitive information inside/outside Jenkins.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-02-27
Other sources
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query.
— NVD
XML external entity (XXE) vulnerability in Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1809?
CVE-2015-1809 is classified as a medium severity vulnerability.
How do I fix CVE-2015-1809?
To fix CVE-2015-1809, upgrade Jenkins to version 1.596.1 or 1.600, or later.
Who is affected by CVE-2015-1809?
CVE-2015-1809 affects Jenkins installations prior to version 1.596.1 and 1.600.
What type of information can be exposed through CVE-2015-1809?
CVE-2015-1809 may expose sensitive information contained in arbitrary XML documents on the server.
Can read access users exploit CVE-2015-1809?
Yes, users with read access in Jenkins can exploit CVE-2015-1809 to access sensitive information.