An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS13Y3JnLTkyd3AtNGgyOM4AAmLE

Moderate EPSS: 0.00686% (0.70933 Percentile) EPSS:

XXE vulnerability in Jenkins Nerrvana Plugin

Affected Packages Affected Versions Fixed Versions
maven:org.jenkins-ci.plugins:nerrvana-plugin <= 1.02.06 No known fixed version

Jenkins Nerrvana Plugin 1.02.06 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

This allows attackers with Overall/Read permission to have Jenkins parse a crafted HTTP request with XML data that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.

Additionally, XML parsing is exposed as a form validation endpoint that does not require POST requests, allowing exploitation by users without Overall/Read permission via CSRF.

References: