Vulnerabilities (CVE)

Filtered by CWE-611
Total 1045 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-43067 1 Dell 3 Unity Operating Environment, Unity Xt Operating Environment, Unityvsa Operating Environment 2023-10-28 N/A 6.5 MEDIUM
Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability. An XXE attack could potentially exploit this vulnerability disclosing local files in the file system.
CVE-2020-2144 1 Jenkins 1 Rundeck 2023-10-25 5.5 MEDIUM 7.1 HIGH
Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2019-10466 1 Jenkins 1 360 Fireline 2023-10-25 5.5 MEDIUM 8.1 HIGH
An XML external entities (XXE) vulnerability in Jenkins 360 FireLine Plugin allows attackers with Overall/Read access to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks.
CVE-2019-10337 1 Jenkins 1 Token Macro 2023-10-25 5.0 MEDIUM 7.5 HIGH
An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks.
CVE-2020-2171 1 Jenkins 1 Rapiddeploy 2023-10-25 6.5 MEDIUM 8.8 HIGH
Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2138 1 Jenkins 1 Cobertura 2023-10-25 5.5 MEDIUM 7.1 HIGH
Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2019-16549 1 Jenkins 1 Maven 2023-10-25 6.8 MEDIUM 8.1 HIGH
Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks, allowing man-in-the-middle attackers to have Jenkins parse crafted XML documents.
CVE-2019-10309 1 Jenkins 1 Self-organizing Swarm Modules 2023-10-25 4.8 MEDIUM 9.3 CRITICAL
Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read arbitrary files from Swarm clients.
CVE-2020-2092 1 Jenkins 1 Robot Framework 2023-10-25 6.5 MEDIUM 8.8 HIGH
Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing users with Job/Configure to have Jenkins parse crafted XML documents.
CVE-2020-2178 1 Jenkins 1 Parasoft Findings 2023-10-25 5.5 MEDIUM 7.1 HIGH
Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2120 1 Jenkins 1 Fitnesse 2023-10-25 6.5 MEDIUM 8.8 HIGH
Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
CVE-2021-21642 1 Jenkins 1 Config File Provider 2023-10-25 5.5 MEDIUM 8.1 HIGH
Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2284 1 Jenkins 1 Liquibase Runner 2023-10-25 5.5 MEDIUM 7.1 HIGH
Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2245 1 Jenkins 1 Valgrind 2023-10-25 5.5 MEDIUM 7.1 HIGH
Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2108 1 Jenkins 1 Websphere Deployer 2023-10-25 6.5 MEDIUM 7.6 HIGH
Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Job/Configure permissions.
CVE-2020-2115 1 Jenkins 1 Nunit 2023-10-25 6.5 MEDIUM 8.8 HIGH
Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
CVE-2019-10327 1 Jenkins 1 Pipeline Maven Integration 2023-10-25 5.5 MEDIUM 8.1 HIGH
An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed attackers able to control a temporary directory's content on the agent running the Maven build to have Jenkins parse a maliciously crafted XML file that uses external entities for extraction of secrets from the Jenkins master, server-side request forgery, or denial-of-service attacks.
CVE-2021-21672 1 Jenkins 1 Selenium Html Report 2023-10-25 4.0 MEDIUM 4.3 MEDIUM
Jenkins Selenium HTML report Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2324 1 Jenkins 1 Cvs 2023-10-25 5.0 MEDIUM 7.5 HIGH
Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2247 1 Jenkins 1 Klocwork Analysis 2023-10-25 4.0 MEDIUM 6.5 MEDIUM
Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.