Total
1045 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-43067 | 1 Dell | 3 Unity Operating Environment, Unity Xt Operating Environment, Unityvsa Operating Environment | 2023-10-28 | N/A | 6.5 MEDIUM |
Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability. An XXE attack could potentially exploit this vulnerability disclosing local files in the file system. | |||||
CVE-2020-2144 | 1 Jenkins | 1 Rundeck | 2023-10-25 | 5.5 MEDIUM | 7.1 HIGH |
Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |||||
CVE-2019-10466 | 1 Jenkins | 1 360 Fireline | 2023-10-25 | 5.5 MEDIUM | 8.1 HIGH |
An XML external entities (XXE) vulnerability in Jenkins 360 FireLine Plugin allows attackers with Overall/Read access to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks. | |||||
CVE-2019-10337 | 1 Jenkins | 1 Token Macro | 2023-10-25 | 5.0 MEDIUM | 7.5 HIGH |
An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks. | |||||
CVE-2020-2171 | 1 Jenkins | 1 Rapiddeploy | 2023-10-25 | 6.5 MEDIUM | 8.8 HIGH |
Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |||||
CVE-2020-2138 | 1 Jenkins | 1 Cobertura | 2023-10-25 | 5.5 MEDIUM | 7.1 HIGH |
Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |||||
CVE-2019-16549 | 1 Jenkins | 1 Maven | 2023-10-25 | 6.8 MEDIUM | 8.1 HIGH |
Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks, allowing man-in-the-middle attackers to have Jenkins parse crafted XML documents. | |||||
CVE-2019-10309 | 1 Jenkins | 1 Self-organizing Swarm Modules | 2023-10-25 | 4.8 MEDIUM | 9.3 CRITICAL |
Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read arbitrary files from Swarm clients. | |||||
CVE-2020-2092 | 1 Jenkins | 1 Robot Framework | 2023-10-25 | 6.5 MEDIUM | 8.8 HIGH |
Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing users with Job/Configure to have Jenkins parse crafted XML documents. | |||||
CVE-2020-2178 | 1 Jenkins | 1 Parasoft Findings | 2023-10-25 | 5.5 MEDIUM | 7.1 HIGH |
Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |||||
CVE-2020-2120 | 1 Jenkins | 1 Fitnesse | 2023-10-25 | 6.5 MEDIUM | 8.8 HIGH |
Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks. | |||||
CVE-2021-21642 | 1 Jenkins | 1 Config File Provider | 2023-10-25 | 5.5 MEDIUM | 8.1 HIGH |
Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |||||
CVE-2020-2284 | 1 Jenkins | 1 Liquibase Runner | 2023-10-25 | 5.5 MEDIUM | 7.1 HIGH |
Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |||||
CVE-2020-2245 | 1 Jenkins | 1 Valgrind | 2023-10-25 | 5.5 MEDIUM | 7.1 HIGH |
Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |||||
CVE-2020-2108 | 1 Jenkins | 1 Websphere Deployer | 2023-10-25 | 6.5 MEDIUM | 7.6 HIGH |
Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Job/Configure permissions. | |||||
CVE-2020-2115 | 1 Jenkins | 1 Nunit | 2023-10-25 | 6.5 MEDIUM | 8.8 HIGH |
Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks. | |||||
CVE-2019-10327 | 1 Jenkins | 1 Pipeline Maven Integration | 2023-10-25 | 5.5 MEDIUM | 8.1 HIGH |
An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed attackers able to control a temporary directory's content on the agent running the Maven build to have Jenkins parse a maliciously crafted XML file that uses external entities for extraction of secrets from the Jenkins master, server-side request forgery, or denial-of-service attacks. | |||||
CVE-2021-21672 | 1 Jenkins | 1 Selenium Html Report | 2023-10-25 | 4.0 MEDIUM | 4.3 MEDIUM |
Jenkins Selenium HTML report Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |||||
CVE-2020-2324 | 1 Jenkins | 1 Cvs | 2023-10-25 | 5.0 MEDIUM | 7.5 HIGH |
Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |||||
CVE-2020-2247 | 1 Jenkins | 1 Klocwork Analysis | 2023-10-25 | 4.0 MEDIUM | 6.5 MEDIUM |
Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |