CVEs Blog | G5 Cyber Security

CVE-2020-2144 – Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parse

Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2144

Reference (s):

Exit mobile version