CVE-2015-5319XML External Entity (XXE) Injection in Jenkins

Severity
5.0MEDIUMNVD
EPSS
0.3%
top 45.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 25
Latest updateMay 13

Description

XML external entity (XXE) vulnerability in the create-job CLI command in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to read arbitrary files via a crafted job configuration that is then used in an "XML-aware tool," as demonstrated by get-job and update-job.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDjenkins/jenkins1.625.1+1
NVDredhat/openshift3.1+1

🔴Vulnerability Details

3
GHSA
Jenkins has XML External Entity (XXE) Vulnerability in Job Configuration via CLI2022-05-13
OSV
Jenkins has XML External Entity (XXE) Vulnerability in Job Configuration via CLI2022-05-13
CVEList
CVE-2015-5319: XML external entity (XXE) vulnerability in the create-job CLI command in Jenkins before 12015-11-25

📋Vendor Advisories

2
Jenkins
Jenkins Security Advisory 2015-11-112015-11-11
Red Hat
jenkins: XXE injection into job configurations via CLI (SECURITY-173)2015-11-11

💬Community

1
Bugzilla
CVE-2015-5319 jenkins: XXE injection into job configurations via CLI (SECURITY-173)2015-11-16
CVE-2015-5319 — XML External Entity (XXE) Injection | cvebase