XML external entity (XXE) attacks in Jenkins Xcode integration Plugin
High severity
GitHub Reviewed
Published
Mar 18, 2022
to the GitHub Advisory Database
•
Updated Dec 7, 2023
Package
Affected versions
< 2.0.15
Patched versions
2.0.15
Description
Published by the National Vulnerability Database
May 11, 2021
Reviewed
May 19, 2021
Published to the GitHub Advisory Database
Mar 18, 2022
Last updated
Dec 7, 2023
Jenkins Xcode integration Plugin 2.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
References