CVEs Blog | G5 Cyber Security

CVE-2020-2120 – Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parse

Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2120

Reference (s):

Exit mobile version