Lucene search

K
githubGitHub Advisory DatabaseGHSA-W898-3PH8-5PGM
HistoryMay 24, 2022 - 4:44 p.m.

Jenkins Self-Organizing Swarm Plug-in Modules Plugin XXE vulnerability via UDP broadcast response

2022-05-2416:44:54
CWE-611
GitHub Advisory Database
github.com
3
jenkins
self-organizing
plugin
xxe
vulnerability
udp
discovery
xml
parser
external entities

CVSS2

4.8

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:P/I:N/A:P

CVSS3

9.3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H

EPSS

0.003

Percentile

66.2%

Jenkins Swarm Plugin allows clients to auto-discover Jenkins instances on the same network through a UDP discovery request. Responses to this request are XML documents.

Swarm Plugin does not configure the XML parser in a way that would prevent XML External Entity (XXE) processing. This allows unauthenticated attackers on the same network to have Swarm clients parse a maliciously crafted XML response that uses external entities to read arbitrary files from the Swarm client or denial-of-service attacks.

As of publication of this advisory, there is no fix.

Affected configurations

Vulners
Node
org.jenkins-ci.pluginsswarmRange3.15
VendorProductVersionCPE
org.jenkins-ci.pluginsswarm*cpe:2.3:a:org.jenkins-ci.plugins:swarm:*:*:*:*:*:*:*:*

CVSS2

4.8

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:P/I:N/A:P

CVSS3

9.3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H

EPSS

0.003

Percentile

66.2%