CVE-2018-1000009 Information
Feb 14, 2021
cve
Description
Jenkins Checkstyle Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master perform server-side request forgery or denial-of-service attacks.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://jenkins.io/security/advisory/2018-01-22/
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: