CVE-2019-10309
3Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 1.8%
probabilidad de explotación
1.8%top 24% de las CVE
explotación observada
noninguna fuente lo reporta
Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read arbitrary files from Swarm clients.
Productos afectados
Jenkins project · Jenkins Self-Organizing Swarm Plug-in Modules Plugin