[MAVEN:GHSA-M53P-F25Q-Q6FG] XXE vulnerability in Jenkins Robot Framework Plugin

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

Robot Framework Plugin 2.0.0 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.

This allows a user able to control the input files for the 'Publish Robot Framework' post-build step to have Jenkins parse a crafted file that uses external entities for extraction of secrets from the Jenkins controller, server-side request forgery, or denial-of-service attacks.

Robot Framework Plugin 2.0.1 disables external entity resolution for its XML parser.

Package Affected Version
pkg:maven/org.jenkins-ci.plugins/robot < 2.0.1
Package Fixed Version
pkg:maven/org.jenkins-ci.plugins/robot = 2.0.1
ID
MAVEN:GHSA-M53P-F25Q-Q6FG
Severity
high
URL
https://github.com/advisories/GHSA-m53p-f25q-q6fg
Published
2022-05-24T17:06:23
(2 years ago)
Modified
2023-12-22T13:58:14
(9 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/robot org.jenkins-ci.plugins robot < 2.0.1
Fixed pkg:maven/org.jenkins-ci.plugins/robot org.jenkins-ci.plugins robot = 2.0.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...