HTTP: Jenkins Generic Webhook Trigger Plugin External Entity Injection

This signature detects attempts to exploit a known vulnerability against Jenkins Generic Webhook Trigger Plugin. A successful attack can lead to sensitive information disclosure.

Extended Description

Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Affected Products

Jenkins generic_webhook_trigger

Short Name
HTTP:MISC:JENKINS-WEBHOOK-XXE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2021-21669 Entity External Generic Injection Jenkins Plugin Trigger Webhook
Release Date
08/04/2021
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3407
False Positive
Unknown
Vendors

Jenkins

CVSS Score

7.5

Found a potential security threat?