First published: Wed Jan 29 2020(Updated: )
Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Job/Configure permissions.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Websphere Deployer | <=1.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-2108.
The title of this Jenkins vulnerability is 'Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks'.
The severity of CVE-2020-2108 is high with a CVSS score of 7.6.
This vulnerability can be exploited by a user with Job/Configure permissions to launch XXE attacks.
Yes, a fix is available. Users should update to Jenkins WebSphere Deployer Plugin version 1.6.2 or later.