First published: Tue Jun 05 2018(Updated: )
A XML external entity processing vulnerability exists in Jenkins Black Duck Hub Plugin 3.1.0 and older in PostBuildScanDescriptor.java that allows attackers with Overall/Read permission to make Jenkins process XML eternal entities in an XML document.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Black Duck Hub | <=3.1.0 | |
maven/com.blackducksoftware.integration:blackduck-hub | <=3.1.0 | 4.0.0 |
<=3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000198 has a CVSS score that indicates it has a medium severity level due to its ability to allow XML external entity processing.
To fix CVE-2018-1000198, upgrade the Jenkins Black Duck Hub Plugin to version 4.0.0 or later.
Any Jenkins instance using Black Duck Hub Plugin version 3.1.0 or older is affected by CVE-2018-1000198.
CVE-2018-1000198 is an XML external entity processing vulnerability.
An attacker needs Overall/Read permission to exploit CVE-2018-1000198.