Lucene search

K
cvelistJenkinsCVELIST:CVE-2019-10309
HistoryApr 30, 2019 - 12:25 p.m.

CVE-2019-10309

2019-04-3012:25:17
jenkins
www.cve.org
4

AI Score

9.2

Confidence

High

EPSS

0.003

Percentile

66.2%

Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read arbitrary files from Swarm clients.

CNA Affected

[
  {
    "product": "Jenkins Self-Organizing Swarm Plug-in Modules Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "status": "affected",
        "version": "3.15 and earlier"
      }
    ]
  }
]

AI Score

9.2

Confidence

High

EPSS

0.003

Percentile

66.2%