GHSA-4rj6-9pjh-882r
Dashboard / Vulnerabilities / GHSA-4rj6-9pjh-882r
Summary: Improper Restriction of XML External Entity Reference in Jenkins JUnit Plugin
Details: Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-1000056, https://github.com/jenkinsci/junit-plugin/commit/15f39fc49d9f25bca872badb48e708a8bb815ea7, https://github.com/jenkinsci/junit-plugin, https://jenkins.io/security/advisory/2018-02-05
Affected packages
Package
Name: org.jenkins-ci.plugins:junit
Purl: pkg:maven/org.jenkins-ci.plugins/junit
Affected ranges
Type: ECOSYSTEM
Events:
