CVE-2023-24430: XEE
Published Jan 24, 2023
·Updated
Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Affected Software
2 affected componentsFixes available
Jenkins Semantic Versioning Jenkins<1.15
maven/org.jenkins-ci.plugins:semantic-versioning-plugin<1.15
1.15
Event History
Jan 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 26, 2023
Advisory Published
09:30 PM
Frequently Asked Questions
1
What is CVE-2023-24430?
CVE-2023-24430 is a vulnerability in the Jenkins Semantic Versioning Plugin 1.14 and earlier that allows XML external entity (XXE) attacks.
2
How severe is CVE-2023-24430?
CVE-2023-24430 has a severity keyword of 'critical' and a severity value of 9.8.
3
How does CVE-2023-24430 affect Jenkins Semantic Versioning Plugin?
CVE-2023-24430 affects Jenkins Semantic Versioning Plugin 1.14 and earlier by not configuring its XML parser to prevent XXE attacks.
4
Which version of Jenkins Semantic Versioning Plugin is affected by CVE-2023-24430?
Jenkins Semantic Versioning Plugin versions up to and excluding 1.15 are affected by CVE-2023-24430.
5
How can CVE-2023-24430 be mitigated?
To mitigate CVE-2023-24430, it is recommended to upgrade Jenkins Semantic Versioning Plugin to version 1.15 or later.