GHSA-x58r-wxc3-7pqr

Suggest an improvement
Source
https://github.com/advisories/GHSA-x58r-wxc3-7pqr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x58r-wxc3-7pqr/GHSA-x58r-wxc3-7pqr.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-x58r-wxc3-7pqr
Aliases
Published
2022-05-24T17:33:07Z
Modified
2024-02-16T08:19:33.376789Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
XXE vulnerability in Jenkins Mercurial Plugin
Details

Jenkins Mercurial Plugin prior to 2.12, 2.10.1, 2.9.1, and 2.8.1 does not configure its XML changelog parser to prevent XML external entity (XXE) attacks.

This allows attackers able to control an agent process to have Jenkins parse a crafted changelog file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.

Mercurial Plugin 2.12, 2.10.1, 2.9.1, and 2.8.1 disables external entity resolution for its XML parser.

Database specific
{
    "nvd_published_at": "2020-11-04T15:15:00Z",
    "cwe_ids": [
        "CWE-611"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2022-06-23T23:20:09Z"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:mercurial

Package

Name
org.jenkins-ci.plugins:mercurial
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/mercurial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.11
Fixed
2.12

Affected versions

2.*

2.11

Maven / org.jenkins-ci.plugins:mercurial

Package

Name
org.jenkins-ci.plugins:mercurial
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/mercurial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.10
Fixed
2.10.1

Affected versions

2.*

2.10

Maven / org.jenkins-ci.plugins:mercurial

Package

Name
org.jenkins-ci.plugins:mercurial
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/mercurial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.9
Fixed
2.9.1

Affected versions

2.*

2.9

Maven / org.jenkins-ci.plugins:mercurial

Package

Name
org.jenkins-ci.plugins:mercurial
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/mercurial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.8.1

Affected versions

1.*

1.37
1.38
1.39
1.40
1.41
1.42
1.43
1.44
1.45
1.46
1.47
1.48-beta-1
1.48
1.49
1.50-beta-1
1.50-beta-2
1.50
1.50.1
1.51-beta-1
1.51-beta-2
1.51-beta-3
1.51
1.52
1.53
1.54
1.55
1.56
1.57
1.58-beta-1
1.58
1.59
1.60
1.61

2.*

2.0-alpha-1
2.0-alpha-4
2.0-beta-1
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
2.8