Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-10309


Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read arbitrary files from Swarm clients.


Published

2019-04-30T13:29:05.407

Last Modified

2024-11-21T04:18:51.743

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 9.3 (CRITICAL)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:P/I:N/A:P

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

6.5

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins self-organizing_swarm_modules - Yes

References