CVE-2015-1811: XEE
This vulnerability allows attackers to create malicious XML documents and feed that into Jenkins, which causes Jenkins to retrieve arbitrary XML document on the server, resulting in the exposure of sensitive information inside/outside Jenkins.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-02-27
Other sources
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via a crafted XML document.
— NVD
XML external entity (XXE) vulnerability in Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via a crafted XML document.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1811?
CVE-2015-1811 is considered a high severity vulnerability due to its ability to expose sensitive information.
How do I fix CVE-2015-1811?
To fix CVE-2015-1811, upgrade Jenkins to a version above 1.600 or 1.596.1 depending on the specific build you are using.
What impact does CVE-2015-1811 have on Jenkins users?
CVE-2015-1811 allows attackers to exploit Jenkins by processing malicious XML, potentially leading to unauthorized data exposure.
Which versions of Jenkins are affected by CVE-2015-1811?
CVE-2015-1811 affects Jenkins versions below 1.596.1 and 1.600.
Is there a workaround for CVE-2015-1811?
There is no specific workaround for CVE-2015-1811; updating to a patched version is the recommended action.