CVE-2023-28681

Description

Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Risk Information

Base Score
8.2
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
EPSS Score
Exploitation Probability
0.277

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2023-28681 are affected in Jenkins - vs-code-metrics 1.7Windows
Vulnerabilities CVE-2023-28681 are affected in Jenkins - vs-code-metrics for Linux 1.7Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234