XML injection (XXE) In org.jenkins-ci.main:jenkins-core
Description
XML external entity (XXE) vulnerability in Jenkins XML external entity (XXE) vulnerability in Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 1.600, 1.596.1 |
Aliases
1. 2. 3. 4.
References
1. 2.