CVE-2021-43577: XEE
Published Nov 12, 2021
·Updated
Jenkins OWASP Dependency-Check Plugin 5.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Affected Software
2 affected componentsFixes available
maven/org.jenkins-ci.plugins:dependency-check-jenkins-plugin<=5.1.1
5.1.2
Jenkins Owasp Dependency-check Jenkins<=5.1.1
Event History
Nov 12, 2021
CVE Published
via MITRE·10:35 AM
Data Sourced
via MITRE·10:35 AM
Description
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
May 24, 2022
Advisory Published
07:20 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-43577?
CVE-2021-43577 is classified as a high severity vulnerability due to its potential to allow XML external entity (XXE) attacks.
2
How do I fix CVE-2021-43577?
To fix CVE-2021-43577, upgrade the Jenkins OWASP Dependency-Check Plugin to version 5.1.2 or later.
3
What versions are affected by CVE-2021-43577?
CVE-2021-43577 affects Jenkins OWASP Dependency-Check Plugin version 5.1.1 and earlier.
4
What kind of attacks does CVE-2021-43577 enable?
CVE-2021-43577 enables XML external entity (XXE) attacks, which can expose sensitive data or facilitate further attacks.
5
Is CVE-2021-43577 specific to Jenkins?
Yes, CVE-2021-43577 is a vulnerability specifically related to the Jenkins OWASP Dependency-Check Plugin.