Loading HuntDB...

GHSA-wcrg-92wp-4h28

GitHub Security Advisory

XXE vulnerability in Jenkins Nerrvana Plugin

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Jenkins Nerrvana Plugin 1.02.06 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

This allows attackers with Overall/Read permission to have Jenkins parse a crafted HTTP request with XML data that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.

Additionally, XML parsing is exposed as a form validation endpoint that does not require POST requests, allowing exploitation by users without Overall/Read permission via CSRF.

Affected Packages

Maven org.jenkins-ci.plugins:nerrvana-plugin
Affected versions: 0 (last affected: 1.02.06)

Related CVEs

Key Information

GHSA ID
GHSA-wcrg-92wp-4h28
Published
May 24, 2022 5:30 PM
Last Modified
October 27, 2023 11:58 AM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:nerrvana-plugin
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 27, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.