CVE-2022-45395
Description
Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Jenkins CCCC Plugin 0.6 and earlier is vulnerable to XXE attacks due to unsecured XML parser configuration.
The Jenkins CCCC Plugin (up to version 0.6) fails to securely configure its XML parser, allowing XML External Entity (XXE) attacks [1]. This vulnerability arises because the plugin does not disable external entity processing or DTD loading in the XML parser, enabling attackers to exploit the parser's behavior [2].
An attacker with the ability to supply a crafted XML file—for example, by uploading a malicious configuration to a Jenkins project—can exploit this vulnerability. No special privileges are required beyond typical Jenkins job configuration access, making the attack surface significant for environments where untrusted users can create or modify jobs [1]. The plugin's default configuration does not enforce secure parsing, leaving it exposed.
Successful exploitation can lead to information disclosure, as the attacker may read arbitrary files on the Jenkins controller host (e.g., secrets, credentials, configuration files) via external entities. It may also enable server-side request forgery (SSRF) attacks against internal network resources, potentially compromising additional services [2].
As of the Jenkins Security Advisory published on November 15, 2022, no fix has been released for the CCCC Plugin [1]. Administrators are advised to either disable the plugin or restrict its use to trusted users. The plugin's source code is available on GitHub [4], but no patched version has been provided. Monitoring for updates from the Jenkins project is recommended.
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.thalesgroup.jenkins-ci.plugins:ccccMaven | <= 0.6 | — |
Affected products
3- Range: <=0.6
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-f3gj-hvv4-f57vghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-45395ghsaADVISORY
- www.openwall.com/lists/oss-security/2022/11/15/4ghsamailing-listWEB
- www.jenkins.io/security/advisory/2022-11-15/ghsaWEB
News mentions
1- Jenkins Security Advisory 2022-11-15Jenkins Security Advisories · Nov 15, 2022