CVE-2023-24441: XEE
Published Jan 24, 2023
·Updated
Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Affected Software
2 affected componentsFixes available
Jenkins Mstest Jenkins<=1.0.0
maven/org.jvnet.hudson.plugins:mstest<1.0.1
1.0.1
Event History
Jan 24, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Jan 26, 2023
Advisory Published
09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-24441?
CVE-2023-24441 is considered a moderate severity vulnerability due to the potential for XML external entity (XXE) attacks.
2
How do I fix CVE-2023-24441?
To fix CVE-2023-24441, update the Jenkins MSTest Plugin to version 1.0.1 or later.
3
What is the impact of CVE-2023-24441?
The impact of CVE-2023-24441 can potentially allow an attacker to extract data from the server through XML external entity processing.
4
Which versions of Jenkins MSTest Plugin are affected by CVE-2023-24441?
CVE-2023-24441 affects Jenkins MSTest Plugin version 1.0.0 and earlier.
5
Is there a workaround for CVE-2023-24441?
There are no known workarounds for CVE-2023-24441; updating to the latest version is the recommended solution.