CVE-2019-10309
9.3
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
Exploitability: 2.8 / Impact: 5.8
Source: NVD
Description
Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read arbitrary files from Swarm clients.
Affected (1)
Products: Jenkins: Self Organizing Swarm Modules
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
References (8)
Source: jenkinsci-cert@googlegroups.com
Mailing ListThird Party Advisory
Source: jenkinsci-cert@googlegroups.com
Source: jenkinsci-cert@googlegroups.com
Vendor Advisory
Source: jenkinsci-cert@googlegroups.com
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.