CVE-2020-2304: XEE
A flaw was found in the subversion Jenkins plugin. The XML parser is not properly configured to prevent XML external entity (XXE) attacks allowing an attacker the ability to control an agent process and have Jenkins parse a crafted changelog file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery. The highest threat from this vulnerability is to data confidentiality.
Other sources
Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
This allows attackers able to control an agent process to have Jenkins parse a crafted changelog file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.
— Red Hat
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-2304?
CVE-2020-2304 is a vulnerability in the Jenkins Subversion Plugin that allows an attacker to control an agent process and extract secrets.
What is the severity of CVE-2020-2304?
CVE-2020-2304 has a severity score of 6.5, which is considered high.
How does CVE-2020-2304 affect Jenkins Subversion Plugin?
CVE-2020-2304 affects Jenkins Subversion Plugin versions 2.13.1 and earlier.
How can I fix CVE-2020-2304?
To fix CVE-2020-2304, you should update Jenkins Subversion Plugin to version 2.13.2.
Where can I find more information about CVE-2020-2304?
You can find more information about CVE-2020-2304 in the Jenkins security advisory and the Red Hat Security Advisory.