CVE-2022-41226
unknown
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
โ
Description
Jenkins Compuware Common Configuration Plugin vulnerable to Improper Restriction of XML External Entity Reference
Predictions
Exploit likelihood
30%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | com.compuware.jenkins:compuware-common-configuration | <1.0.15 | 1.0.15 |
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-41226
- https://github.com/jenkinsci/compuware-common-configuration-plugin/pull/24
- https://github.com/jenkinsci/compuware-common-configuration-plugin/commit/351a46798cdc10479cb6966f05a51bc2174806a0
- https://github.com/jenkinsci/compuware-common-configuration-plugin/commit/8410fd5e0a619200f5bc2e906ecba940e8506436
- https://github.com/jenkinsci/compuware-common-configuration-plugin/commit/a92f1fba5ab375cfcceed92a16666a4c709e0f3b
- https://github.com/jenkinsci/compuware-common-configuration-plugin
- https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2832
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.