QID 997466
Date Published: 2024-02-26
QID 997466: Java (Maven) Security Update for org.jenkins-ci.main:jenkins-core (GHSA-qj27-w92h-fc9r)
XML external entity (XXE) vulnerability in Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-qj27-w92h-fc9r for updates and patch information.
Vendor References
- GHSA-qj27-w92h-fc9r -
github.com/advisories/GHSA-qj27-w92h-fc9r
CVEs related to QID 997466
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qj27-w92h-fc9r | org.jenkins-ci.main:jenkins-core |
|