Lucene search

K
cveJenkinsCVE-2022-41241
HistorySep 21, 2022 - 4:15 p.m.

CVE-2022-41241

2022-09-2116:15:10
CWE-611
jenkins
web.nvd.nist.gov
50
2
cve-2022-41241
jenkins
rqm plugin
xml parser
xxe vulnerability
nvd

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9.2

Confidence

High

EPSS

0.002

Percentile

51.7%

Jenkins RQM Plugin 2.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Affected configurations

Nvd
Node
jenkinsrqmRange2.8jenkins
VendorProductVersionCPE
jenkinsrqm*cpe:2.3:a:jenkins:rqm:*:*:*:*:*:jenkins:*:*

CNA Affected

[
  {
    "product": "Jenkins RQM Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThanOrEqual": "2.8",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "unknown",
        "version": "next of 2.8",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9.2

Confidence

High

EPSS

0.002

Percentile

51.7%

Related for CVE-2022-41241