CVE-2015-5319 — XML External Entity (XXE) Injection in Jenkins
Severity
5.0MEDIUMNVD
EPSS
0.3%
top 45.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 25
Latest updateMay 13
Description
XML external entity (XXE) vulnerability in the create-job CLI command in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to read arbitrary files via a crafted job configuration that is then used in an "XML-aware tool," as demonstrated by get-job and update-job.
CVSS vector
AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9
Affected Packages2 packages
🔴Vulnerability Details
3CVEList▶
CVE-2015-5319: XML external entity (XXE) vulnerability in the create-job CLI command in Jenkins before 1↗2015-11-25
📋Vendor Advisories
2💬Community
1Bugzilla
▶