CVEs Blog | G5 Cyber Security

CVE-2020-2138 – Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML pars

Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2138

Reference (s):

Exit mobile version