CVE Database
/

CVE-2019-10309

Back to search

CVE-2019-10309

Published: Apr 30, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read arbitrary files from Swarm clients.

VendorProductVersions

Jenkins project

Jenkins Self-Organizing Swarm Plug-in Modules Plugin

affected
3.15 and earlier

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now