First published: Thu Jun 30 2022(Updated: )
Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Recipe | <=1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-34793.
The severity of CVE-2022-34793 is rated as high with a CVSS score of 8.8.
Jenkins Recipe Plugin is a plugin for Jenkins that allows users to define and manage recipes for software projects.
Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
To fix this vulnerability, you should upgrade to a version of Jenkins Recipe Plugin that is not affected by the issue.