PT-2026-51813 · Jenkins · Assembla Plugin
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Assembla Plugin versions prior to 1.5
Description
The XML parser is not configured to prevent XML external entity (XXE) attacks. This allows attackers who can control the responses from the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery (SSRF), which is a technique used to induce the server to make requests to an unintended location.
Recommendations
Update Jenkins Assembla Plugin to version 1.5 or later.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Assembla Plugin