CVE-2023-28685: XEE
Published Mar 21, 2023
·Updated
Jenkins AbsInt a³ Plugin 1.1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Affected Software
1 affected component
Jenkins Absint A3 Jenkins<=1.1.0
Event History
Mar 21, 2023
CVE Published
via MITRE·03:53 PM
Data Sourced
via MITRE·03:53 PM
Description
Mar 22, 2023
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-28685?
CVE-2023-28685 has been classified as having a high severity due to the potential for XML external entity (XXE) attacks.
2
How do I fix CVE-2023-28685?
To fix CVE-2023-28685, update the Jenkins AbsInt a³ Plugin to version 1.1.1 or later, which properly configures the XML parser.
3
What systems are affected by CVE-2023-28685?
CVE-2023-28685 affects all versions up to and including 1.1.0 of the Jenkins AbsInt a³ Plugin.
4
What type of vulnerability is CVE-2023-28685?
CVE-2023-28685 is an XML External Entity (XXE) vulnerability that can lead to data exposure and other attacks.
5
Is there a workaround for CVE-2023-28685?
There is no known workaround for CVE-2023-28685; the only mitigation is to upgrade to the patched version of the plugin.