← Back

CVE-2019-10309

nvd nist
Published: Apr 30, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.3
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
Exploitability: 2.8 / Impact: 5.8
Source: NVD

Description

Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read arbitrary files from Swarm clients.

Affected (1)

1 product
Self Organizing Swarm Modules
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (8)

Source: jenkinsci-cert@googlegroups.com
Mailing ListThird Party Advisory
Source: jenkinsci-cert@googlegroups.com
Source: jenkinsci-cert@googlegroups.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.