VYPR
High severityNVD Advisory· Published Jun 30, 2022· Updated Aug 3, 2024

CVE-2022-34793

CVE-2022-34793

Description

Jenkins Recipe Plugin 1.2 and earlier fails to disable XML external entity processing, enabling XXE attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Jenkins Recipe Plugin 1.2 and earlier fails to disable XML external entity processing, enabling XXE attacks.

Vulnerability

Description

The Jenkins Recipe Plugin, versions 1.2 and earlier, does not configure its XML parser to disable XML external entity (XXE) processing. This oversight means that when the plugin parses XML data, it can resolve external entities defined within the XML document, a classic XXE vulnerability [1][2].

Exploitation

Conditions

An attacker would need the ability to supply a crafted XML file to the Recipe Plugin. Since Jenkins often handles user-provided configuration files or imported data, a malicious XML payload could be uploaded or posted to a Jenkins instance that uses the affected plugin. The attacker does not require prior authentication if the plugin processes untrusted input from unauthenticated users, though the specific attack vector depends on how the plugin ingests XML [1].

Impact

Successful exploitation allows an attacker to read arbitrary files from the Jenkins server's file system, perform server-side request forgery (SSRF), or in some configurations, cause denial of service. An XXE attack could also lead to information disclosure, potentially exposing sensitive configuration data or credentials stored on the server [2].

Mitigation

Users should upgrade the Recipe Plugin to version 1.3 or later, which includes a fix that disables XXE processing by default. Administrators who cannot immediately upgrade should review the plugin's XML processing logic and apply workarounds such as restricting plugin usage or implementing additional input validation [1].

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins:recipeMaven
<= 1.2

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.