First published: Thu Apr 16 2020(Updated: )
Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Parasoft Findings | <=10.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-2178 has a CVSS score of 5.5 which indicates a medium severity vulnerability.
To fix CVE-2020-2178, you should upgrade to Jenkins Parasoft Findings Plugin version 10.4.4 or later.
CVE-2020-2178 is an XML External Entity (XXE) vulnerability that can lead to sensitive data exposure.
Jenkins Parasoft Findings Plugin versions up to and including 10.4.3 are affected by CVE-2020-2178.
Yes, CVE-2020-2178 can be exploited remotely under certain conditions, allowing attackers to access sensitive information.