cbcvebase.
CVE-2020-2284
published 2020-09-23

CVE-2020-2284: Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

high7.1CVSS 3.1
AVNACLPRLUINSUCHILAN
Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Affected

10 ranges
VendorProductVersion rangeFixed in
jenkinsemail_extension_plugin
jenkinsimplied_labels_plugin
jenkinsliquibase_changesets_evaluated_by_the_plugin
jenkinsliquibase_runner<= 1.4.5
jenkinsliquibase_runner_plugin
jenkinslockable_resources_plugin
jenkinsscript_security_plugin
jenkinswarnings_next_generation_plugin
jenkinswarnings_plugin
jenkins_projectjenkins_liquibase_runner_pluginunspecified – 1.4.5