GHSA-wcrg-92wp-4h28
GitHub Security Advisory
XXE vulnerability in Jenkins Nerrvana Plugin
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Jenkins Nerrvana Plugin 1.02.06 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
This allows attackers with Overall/Read permission to have Jenkins parse a crafted HTTP request with XML data that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.
Additionally, XML parsing is exposed as a form validation endpoint that does not require POST requests, allowing exploitation by users without Overall/Read permission via CSRF.
Affected Packages
Maven
org.jenkins-ci.plugins:nerrvana-plugin
Affected versions:
0
(last affected: 1.02.06)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 27, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.