CVE-2019-10309

Published Apr 30, 2019

Last updated a year ago

Overview

Description
Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read arbitrary files from Swarm clients.
Source
jenkinsci-cert@googlegroups.com
NVD status
Modified

Social media

Hype score
Not currently trending

Risk scores

CVSS 3.0

Type
Primary
Base score
9.3
Impact score
5.8
Exploitability score
2.8
Vector string
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
Severity
CRITICAL

CVSS 2.0

Type
Primary
Base score
4.8
Impact score
4.9
Exploitability score
6.5
Vector string
AV:A/AC:L/Au:N/C:P/I:N/A:P

Weaknesses

nvd@nist.gov
CWE-611

Configurations