CVE-2022-41241

Severity
9.1CRITICAL
EPSS
0.5%
top 33.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 21
Latest updateSep 22

Description

Jenkins RQM Plugin 2.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages3 packages

CVEListV5jenkins_project/jenkins_rqm_pluginunspecified2.8
NVDjenkins/rqm2.8

🔴Vulnerability Details

3
OSV
Jenkins RQM Plugin vulnerable to Improper Restriction of XML External Entity Reference2022-09-22
GHSA
Jenkins RQM Plugin vulnerable to Improper Restriction of XML External Entity Reference2022-09-22
CVEList
CVE-2022-41241: Jenkins RQM Plugin 22022-09-21

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2022-09-212022-09-21
CVE-2022-41241 (CRITICAL CVSS 9.1) | Jenkins RQM Plugin 2.8 and earlier | cvebase.io