CVEs Blog | G5 Cyber Security

CVE-2020-2247 – Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure

Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2247

Reference (s):

Exit mobile version