XML External Entity (XXE) Processing Vulnerability in Jenkins Black Duck Hub Plugin 3.1.0 and Older

XML External Entity (XXE) Processing Vulnerability in Jenkins Black Duck Hub Plugin 3.1.0 and Older

CVE-2018-1000198 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:N/A:N

A XML external entity processing vulnerability exists in Jenkins Black Duck Hub Plugin 3.1.0 and older in PostBuildScanDescriptor.java that allows attackers with Overall/Read permission to make Jenkins process XML eternal entities in an XML document.

Learn more about our External Network Penetration Testing.