{"id":"GHSA-5wc4-w63v-97c3","summary":"XXE vulnerability in Jenkins Nested View Plugin","details":"Jenkins Nested View Plugin 1.20 and earlier does not configure its XML transformer to prevent XML external entity (XXE) attacks.\n\nThis allows attackers able to configure views to have Jenkins parse a crafted view XML definition that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.\n\nJenkins Nested View Plugin 1.21 disables external entity resolution for its XML transformer.","aliases":["CVE-2021-21680"],"modified":"2024-02-16T08:00:12.898425Z","published":"2022-05-24T19:12:36Z","database_specific":{"cwe_ids":["CWE-611"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-12-15T16:48:02Z","nvd_published_at":"2021-08-31T14:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-21680"},{"type":"WEB","url":"https://github.com/jenkinsci/nested-view-plugin/commit/79787294f034b3009c3de557c6441c9ceba936b8"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/nested-view-plugin"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2021-08-31/#SECURITY-2411"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2021/08/31/1"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:nested-view","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/nested-view"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.21"}]}],"versions":["1.10","1.11","1.12","1.13","1.14","1.17","1.19","1.19.1","1.19.2","1.20","1.6","1.7","1.8","1.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 1.20","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5wc4-w63v-97c3/GHSA-5wc4-w63v-97c3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"}]}