Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
2023-09-06T13:15:10.000
2024-11-21T08:21:56.923
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | jenkins | job_configuration_history | ≤ 1229.v3039470161a_d | Yes |