CVE-2019-10309

CRITICAL

Jenkins Self-Organizing Swarm Modules Plugin - XML External Entity Injection via UDP Broadcast Response

Title source: llm
STIX 2.1

Description

Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read arbitrary files from Swarm clients.

References (4)

Core 4
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2019/04/30/5
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/108159

Scores

CVSS v3 9.3
EPSS 0.0007
EPSS Percentile 21.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H

Details

CWE
CWE-611
Status published
Products (2)
jenkins/self-organizing_swarm_modules
org.jenkins-ci.plugins/swarm 0Maven
Published Apr 30, 2019
Tracked Since Feb 18, 2026