CVE-2022-28155: XEE
Published Mar 29, 2022
·Updated
Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Affected Software
1 affected component
Jenkins Pipeline\<=1.3
Event History
Mar 29, 2022
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-28155?
CVE-2022-28155 is categorized as a high severity vulnerability due to its ability to allow XML External Entity (XXE) attacks.
2
How do I fix CVE-2022-28155?
To fix CVE-2022-28155, upgrade the Jenkins Pipeline: Phoenix AutoTest Plugin to version 1.4 or later.
3
What types of attacks are possible with CVE-2022-28155?
CVE-2022-28155 can be exploited to conduct XML External Entity (XXE) attacks, potentially leading to information disclosure and server-side request forgery.
4
Which versions of the Phoenix AutoTest Plugin are affected by CVE-2022-28155?
CVE-2022-28155 affects versions of the Phoenix AutoTest Plugin up to and including 1.3.
5
What is the nature of the vulnerability in CVE-2022-28155?
CVE-2022-28155 involves improper configuration of the XML parser that fails to protect against XXE attacks.