logo

CVE-2020-2108 org.jenkins-ci.plugins:websphere-deployer

Package

Manager: maven
Name: org.jenkins-ci.plugins:websphere-deployer
Vulnerable Version: >=0 <=1.6.1

Severity

Level: High

CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N

EPSS: 0.0006 pctl0.18803

Details

XXE vulnerability in Jenkins WebSphere Deployer Plugin WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks. This could be exploited by a user with Job/Configure permissions to upload a specially crafted war file containing a `WEB-INF/ibm-web-ext.xml` which is parsed by the plugin.

Metadata

Created: 2022-05-24T17:07:41Z
Modified: 2022-12-19T21:15:52Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f5wx-w2f9-82gh/GHSA-f5wx-w2f9-82gh.json
CWE IDs: ["CWE-611"]
Alternative ID: GHSA-f5wx-w2f9-82gh
Finding: F083
Auto approve: 1