CVE-2020-2315: XEE
Published Nov 4, 2020
·Updated
Jenkins Visualworks Store Plugin 1.1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Affected Software
2 affected componentsFixes available
maven/org.jenkins-ci.plugins:visualworks-store<1.1.4
1.1.4
Jenkins Visualworks Store Jenkins<=1.1.3
Event History
Nov 4, 2020
CVE Published
via MITRE·02:35 PM
Data Sourced
via MITRE·02:35 PM
Description
May 24, 2022
Advisory Published
05:33 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-2315?
CVE-2020-2315 has been assigned a severity level that reflects the potential impact of XML external entity (XXE) attacks if exploited.
2
How do I fix CVE-2020-2315?
To fix CVE-2020-2315, you should upgrade the Jenkins Visualworks Store Plugin to version 1.1.4 or later.
3
What versions are affected by CVE-2020-2315?
CVE-2020-2315 affects Jenkins Visualworks Store Plugin versions 1.1.3 and earlier.
4
What type of attack is possible with CVE-2020-2315?
CVE-2020-2315 allows attackers to execute XML external entity (XXE) attacks due to improper XML parser configuration.
5
Is CVE-2020-2315 a common vulnerability in Jenkins?
Yes, CVE-2020-2315 is a recognized vulnerability affecting the Jenkins environment, specifically in the Visualworks Store Plugin.