First published: Tue Jan 24 2023(Updated: )
Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Semantic Versioning | <1.15 | |
maven/org.jenkins-ci.plugins:semantic-versioning-plugin | <1.15 | 1.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24430 is a vulnerability in the Jenkins Semantic Versioning Plugin 1.14 and earlier that allows XML external entity (XXE) attacks.
CVE-2023-24430 has a severity keyword of 'critical' and a severity value of 9.8.
CVE-2023-24430 affects Jenkins Semantic Versioning Plugin 1.14 and earlier by not configuring its XML parser to prevent XXE attacks.
Jenkins Semantic Versioning Plugin versions up to and excluding 1.15 are affected by CVE-2023-24430.
To mitigate CVE-2023-24430, it is recommended to upgrade Jenkins Semantic Versioning Plugin to version 1.15 or later.