cbcvebase.
CVE-2020-2172
published 2020-04-07

CVE-2020-2172: Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Affected

8 ranges
VendorProductVersion rangeFixed in
jenkinsawseb_deployment_plugin
jenkinscode_coverage_api<= 1.1.4
jenkinscode_coverage_plugin
jenkinsfitnesse_plugin
jenkinsgatling_plugin
jenkinsrunner_plugin
jenkinsxml_input_files_processed_by_the_plugin
jenkins_projectjenkins_code_coverage_api_pluginunspecified – 1.1.4