cbcvebase.
CVE-2020-2305
published 2020-11-04

CVE-2020-2305: Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Affected

19 ranges
VendorProductVersion rangeFixed in
jenkinsactive_directory_plugin
jenkinsansible_plugin
jenkinsappspider_plugin
jenkinsauthentication_cache_in_active_directory_plugin
jenkinsaws_global_configuration_plugin
jenkinsazure_key_vault_plugin
jenkinsfindbugs_plugin
jenkinsids_in_azure_key_vault_plugin
jenkinsjenkins-ci_plugin
jenkinskubernetes_plugin
jenkinsmail_commander_plugin
jenkinsmercurial<= 2.11
jenkinsmercurial_plugin
jenkinssqlplus_script_runner_plugin
jenkinsstatic_analysis_utilities_plugin
jenkinssubversion_plugin
jenkinsvisualworks_store_plugin
jenkinsvmware_lab_manager_slaves_plugin
jenkins_projectjenkins_mercurial_pluginunspecified – 2.11