{"id":"GHSA-m53p-f25q-q6fg","summary":"XXE vulnerability in Jenkins Robot Framework Plugin","details":"Robot Framework Plugin 2.0.0 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.\n\nThis allows a user able to control the input files for the 'Publish Robot Framework' post-build step to have Jenkins parse a crafted file that uses external entities for extraction of secrets from the Jenkins controller, server-side request forgery, or denial-of-service attacks.\n\nRobot Framework Plugin 2.0.1 disables external entity resolution for its XML parser.","aliases":["CVE-2020-2092"],"modified":"2024-02-16T08:22:50.814918Z","published":"2022-05-24T17:06:23Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-12-21T16:42:17Z","nvd_published_at":"2020-01-15T16:15:00Z","cwe_ids":["CWE-611"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-2092"},{"type":"WEB","url":"https://github.com/jenkinsci/robot-plugin/commit/a06626f516e63813db570ff9f3e9b1f76012df59"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/robot-plugin"},{"type":"WEB","url":"https://jenkins.io/security/advisory/2020-01-15/#SECURITY-1698"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:robot","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/robot"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.1"}]}],"versions":["1.2.3","1.3.0","1.3.1","1.3.2","1.4.0","1.4.1","1.4.2","1.4.3","1.5.0","1.6.0","1.6.1","1.6.2","1.6.4","1.6.5","2.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-m53p-f25q-q6fg/GHSA-m53p-f25q-q6fg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L"}]}