CVE-2020-2108 – org.jenkins-ci.plugins:websphere-deployer
Package
Manager: maven
Name: org.jenkins-ci.plugins:websphere-deployer
Vulnerable Version: >=0 <=1.6.1
Severity
Level: High
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
EPSS: 0.0006 pctl0.18803
Details
XXE vulnerability in Jenkins WebSphere Deployer Plugin WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks. This could be exploited by a user with Job/Configure permissions to upload a specially crafted war file containing a `WEB-INF/ibm-web-ext.xml` which is parsed by the plugin.
Metadata
Created: 2022-05-24T17:07:41Z
Modified: 2022-12-19T21:15:52Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f5wx-w2f9-82gh/GHSA-f5wx-w2f9-82gh.json
CWE IDs: ["CWE-611"]
Alternative ID: GHSA-f5wx-w2f9-82gh
Finding: F083
Auto approve: 1