CVE-2020-2304
published 2020-11-04CVE-2020-2304: Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
PriorityP337medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.48%
71.0th percentile
Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | active_directory_plugin | — | — |
| jenkins | ansible_plugin | — | — |
| jenkins | appspider_plugin | — | — |
| jenkins | authentication_cache_in_active_directory_plugin | — | — |
| jenkins | aws_global_configuration_plugin | — | — |
| jenkins | azure_key_vault_plugin | — | — |
| jenkins | findbugs_plugin | — | — |
| jenkins | ids_in_azure_key_vault_plugin | — | — |
| jenkins | jenkins-ci_plugin | — | — |
| jenkins | kubernetes_plugin | — | — |
| jenkins | mail_commander_plugin | — | — |
| jenkins | mercurial_plugin | — | — |
| jenkins | sqlplus_script_runner_plugin | — | — |
| jenkins | static_analysis_utilities_plugin | — | — |
| jenkins | subversion | <= 2.13.1 | — |
| jenkins | subversion_plugin | — | — |
| jenkins | visualworks_store_plugin | — | — |
| jenkins | vmware_lab_manager_slaves_plugin | — | — |
| jenkins_project | jenkins_subversion_plugin | unspecified – 2.13.1 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jenkins-2-plugins/subversion: XML parser is not preventing XML external entity (XXE) attacks
vendor_redhat·2020-11-04·CVSS 6.5
CVE-2020-2304 [MEDIUM] CWE-611 jenkins-2-plugins/subversion: XML parser is not preventing XML external entity (XXE) attacks
jenkins-2-plugins/subversion: XML parser is not preventing XML external entity (XXE) attacks
Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
A flaw was found in the subversion Jenkins plugin. The XML parser is not properly configured to prevent XML external entity (XXE) attacks allowing an attacker the ability to control an agent process and have Jenkins parse a crafted changelog file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery. The highest threat from this vulnerability is to data confidentiality.
Mitigation: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Pl
Jenkins
Jenkins Security Advisory 2020-11-04
vendor_jenkins·2020-11-04·CVSS 9.8
CVE-2020-2299 [CRITICAL] Jenkins Security Advisory 2020-11-04
Title: Jenkins Security Advisory 2020-11-04
Jenkins Security Advisory 2020-11-04
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Active Directory
Plugin
Static Analysis Utilities
Plugin
Ansible
Plugin
AppSpider
Plugin
AWS Global Configuration
Plugin
Azure Key Vault
Plugin
FindBugs
Plugin
Kube
OSV
XXE vulnerability in Jenkins Subversion Plugin
osv·2022-05-24
CVE-2020-2304 [MEDIUM] XXE vulnerability in Jenkins Subversion Plugin
XXE vulnerability in Jenkins Subversion Plugin
Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
This allows attackers able to control an agent process to have Jenkins parse a crafted changelog file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.
Jenkins Subversion Plugin 2.13.2 disables external entity resolution for its XML parser.
GHSA
XXE vulnerability in Jenkins Subversion Plugin
ghsa·2022-05-24
CVE-2020-2304 [MEDIUM] CWE-611 XXE vulnerability in Jenkins Subversion Plugin
XXE vulnerability in Jenkins Subversion Plugin
Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
This allows attackers able to control an agent process to have Jenkins parse a crafted changelog file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.
Jenkins Subversion Plugin 2.13.2 disables external entity resolution for its XML parser.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-11-04
Published