GHSA-xx7g-f287-f9fq
GitHub Security Advisory
XXE vulnerability in Jenkins Liquibase Runner Plugin
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
This allows attackers able to provide Liquibase changesets evaluated by the plugin to have Jenkins parse a crafted XML file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.
Jenkins Liquibase Runner Plugin 1.4.7 no longer parses Liquibase changesets.
Affected Packages
Maven
org.jenkins-ci.plugins:liquibase-runner
Affected versions:
0
(fixed in 1.4.7)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 3, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.