CVE-2022-34793: XEE
Published Jun 30, 2022
·Updated
Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Affected Software
1 affected component
Jenkins Recipe Jenkins<=1.2
Event History
Jun 30, 2022
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-34793.
2
What is the severity of CVE-2022-34793?
The severity of CVE-2022-34793 is rated as high with a CVSS score of 8.8.
3
What is Jenkins Recipe Plugin?
Jenkins Recipe Plugin is a plugin for Jenkins that allows users to define and manage recipes for software projects.
4
What does Jenkins Recipe Plugin 1.2 and earlier do?
Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
5
How can I fix this vulnerability in Jenkins Recipe Plugin?
To fix this vulnerability, you should upgrade to a version of Jenkins Recipe Plugin that is not affected by the issue.