GHSA-g43x-pcc9-f472

    Dashboard / Vulnerabilities / GHSA-g43x-pcc9-f472

    GHSA-g43x-pcc9-f472

    Published: 22 Sept 2022Last Modified: 16 Feb 2024

    Summary: Jenkins Compuware Common Configuration Plugin vulnerable to Improper Restriction of XML External Entity Reference

    Details: Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. This allows attackers able to change the contents of the Topaz Workbench CLI home directory on agents to have Jenkins parse a crafted file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.

    Affected packages

    Package

    Name: com.compuware.jenkins:compuware-common-configuration

    Purl: pkg:maven/com.compuware.jenkins/compuware-common-configuration

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.0.15

    Affected versions

    1.0.10
    1.0.11
    1.0.12
    1.0.13
    1.0.14
    1.0.2
    1.0.3
    1.0.4
    1.0.5
    1.0.6
    1.0.7
    1.0.8
    1.0.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-g43x-pcc9-f472 | CVE-DB