Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-1000008

Jenkins PMD Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 24.1%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2018-1000008
  • Jenkins » Pmd » Version: 1.0
    cpe:2.3:a:jenkins:pmd:1.0
  • Jenkins » Pmd » Version: 1.1
    cpe:2.3:a:jenkins:pmd:1.1
  • Jenkins » Pmd » Version: 1.10
    cpe:2.3:a:jenkins:pmd:1.10
  • Jenkins » Pmd » Version: 1.11
    cpe:2.3:a:jenkins:pmd:1.11
  • Jenkins » Pmd » Version: 1.12
    cpe:2.3:a:jenkins:pmd:1.12
  • Jenkins » Pmd » Version: 1.13
    cpe:2.3:a:jenkins:pmd:1.13
  • Jenkins » Pmd » Version: 1.14
    cpe:2.3:a:jenkins:pmd:1.14
  • Jenkins » Pmd » Version: 1.15
    cpe:2.3:a:jenkins:pmd:1.15
  • Jenkins » Pmd » Version: 1.16
    cpe:2.3:a:jenkins:pmd:1.16
  • Jenkins » Pmd » Version: 1.17
    cpe:2.3:a:jenkins:pmd:1.17
  • Jenkins » Pmd » Version: 1.18
    cpe:2.3:a:jenkins:pmd:1.18
  • Jenkins » Pmd » Version: 1.19
    cpe:2.3:a:jenkins:pmd:1.19
  • Jenkins » Pmd » Version: 1.2
    cpe:2.3:a:jenkins:pmd:1.2
  • Jenkins » Pmd » Version: 1.20
    cpe:2.3:a:jenkins:pmd:1.20
  • Jenkins » Pmd » Version: 1.3
    cpe:2.3:a:jenkins:pmd:1.3
  • Jenkins » Pmd » Version: 1.4
    cpe:2.3:a:jenkins:pmd:1.4
  • Jenkins » Pmd » Version: 1.5
    cpe:2.3:a:jenkins:pmd:1.5
  • Jenkins » Pmd » Version: 1.6
    cpe:2.3:a:jenkins:pmd:1.6
  • Jenkins » Pmd » Version: 1.7
    cpe:2.3:a:jenkins:pmd:1.7
  • Jenkins » Pmd » Version: 1.8
    cpe:2.3:a:jenkins:pmd:1.8
  • Jenkins » Pmd » Version: 1.9
    cpe:2.3:a:jenkins:pmd:1.9
  • Jenkins » Pmd » Version: 2.0
    cpe:2.3:a:jenkins:pmd:2.0
  • Jenkins » Pmd » Version: 2.1
    cpe:2.3:a:jenkins:pmd:2.1
  • Jenkins » Pmd » Version: 2.10
    cpe:2.3:a:jenkins:pmd:2.10
  • Jenkins » Pmd » Version: 2.11
    cpe:2.3:a:jenkins:pmd:2.11
  • Jenkins » Pmd » Version: 2.12
    cpe:2.3:a:jenkins:pmd:2.12
  • Jenkins » Pmd » Version: 2.13
    cpe:2.3:a:jenkins:pmd:2.13
  • Jenkins » Pmd » Version: 2.2
    cpe:2.3:a:jenkins:pmd:2.2
  • Jenkins » Pmd » Version: 2.3
    cpe:2.3:a:jenkins:pmd:2.3
  • Jenkins » Pmd » Version: 2.4
    cpe:2.3:a:jenkins:pmd:2.4
  • Jenkins » Pmd » Version: 2.5
    cpe:2.3:a:jenkins:pmd:2.5
  • Jenkins » Pmd » Version: 2.6
    cpe:2.3:a:jenkins:pmd:2.6
  • Jenkins » Pmd » Version: 2.7
    cpe:2.3:a:jenkins:pmd:2.7
  • Jenkins » Pmd » Version: 2.8
    cpe:2.3:a:jenkins:pmd:2.8
  • Jenkins » Pmd » Version: 2.9
    cpe:2.3:a:jenkins:pmd:2.9
  • Jenkins » Pmd » Version: 3.0
    cpe:2.3:a:jenkins:pmd:3.0
  • Jenkins » Pmd » Version: 3.1
    cpe:2.3:a:jenkins:pmd:3.1
  • Jenkins » Pmd » Version: 3.10
    cpe:2.3:a:jenkins:pmd:3.10
  • Jenkins » Pmd » Version: 3.11
    cpe:2.3:a:jenkins:pmd:3.11
  • Jenkins » Pmd » Version: 3.12
    cpe:2.3:a:jenkins:pmd:3.12
  • Jenkins » Pmd » Version: 3.13
    cpe:2.3:a:jenkins:pmd:3.13
  • Jenkins » Pmd » Version: 3.14
    cpe:2.3:a:jenkins:pmd:3.14
  • Jenkins » Pmd » Version: 3.15
    cpe:2.3:a:jenkins:pmd:3.15
  • Jenkins » Pmd » Version: 3.16
    cpe:2.3:a:jenkins:pmd:3.16
  • Jenkins » Pmd » Version: 3.17
    cpe:2.3:a:jenkins:pmd:3.17
  • Jenkins » Pmd » Version: 3.18
    cpe:2.3:a:jenkins:pmd:3.18
  • Jenkins » Pmd » Version: 3.19
    cpe:2.3:a:jenkins:pmd:3.19
  • Jenkins » Pmd » Version: 3.2
    cpe:2.3:a:jenkins:pmd:3.2
  • Jenkins » Pmd » Version: 3.20
    cpe:2.3:a:jenkins:pmd:3.20
  • Jenkins » Pmd » Version: 3.21
    cpe:2.3:a:jenkins:pmd:3.21
  • Jenkins » Pmd » Version: 3.22
    cpe:2.3:a:jenkins:pmd:3.22
  • Jenkins » Pmd » Version: 3.23
    cpe:2.3:a:jenkins:pmd:3.23
  • Jenkins » Pmd » Version: 3.24
    cpe:2.3:a:jenkins:pmd:3.24
  • Jenkins » Pmd » Version: 3.25
    cpe:2.3:a:jenkins:pmd:3.25
  • Jenkins » Pmd » Version: 3.26
    cpe:2.3:a:jenkins:pmd:3.26
  • Jenkins » Pmd » Version: 3.27
    cpe:2.3:a:jenkins:pmd:3.27
  • Jenkins » Pmd » Version: 3.28
    cpe:2.3:a:jenkins:pmd:3.28
  • Jenkins » Pmd » Version: 3.29
    cpe:2.3:a:jenkins:pmd:3.29
  • Jenkins » Pmd » Version: 3.3
    cpe:2.3:a:jenkins:pmd:3.3
  • Jenkins » Pmd » Version: 3.30
    cpe:2.3:a:jenkins:pmd:3.30
  • Jenkins » Pmd » Version: 3.31
    cpe:2.3:a:jenkins:pmd:3.31
  • Jenkins » Pmd » Version: 3.32
    cpe:2.3:a:jenkins:pmd:3.32
  • Jenkins » Pmd » Version: 3.33
    cpe:2.3:a:jenkins:pmd:3.33
  • Jenkins » Pmd » Version: 3.34
    cpe:2.3:a:jenkins:pmd:3.34
  • Jenkins » Pmd » Version: 3.35
    cpe:2.3:a:jenkins:pmd:3.35
  • Jenkins » Pmd » Version: 3.36
    cpe:2.3:a:jenkins:pmd:3.36
  • Jenkins » Pmd » Version: 3.37
    cpe:2.3:a:jenkins:pmd:3.37
  • Jenkins » Pmd » Version: 3.38
    cpe:2.3:a:jenkins:pmd:3.38
  • Jenkins » Pmd » Version: 3.39
    cpe:2.3:a:jenkins:pmd:3.39
  • Jenkins » Pmd » Version: 3.4
    cpe:2.3:a:jenkins:pmd:3.4
  • Jenkins » Pmd » Version: 3.40
    cpe:2.3:a:jenkins:pmd:3.40
  • Jenkins » Pmd » Version: 3.41
    cpe:2.3:a:jenkins:pmd:3.41
  • Jenkins » Pmd » Version: 3.42
    cpe:2.3:a:jenkins:pmd:3.42
  • Jenkins » Pmd » Version: 3.43
    cpe:2.3:a:jenkins:pmd:3.43
  • Jenkins » Pmd » Version: 3.44
    cpe:2.3:a:jenkins:pmd:3.44
  • Jenkins » Pmd » Version: 3.45
    cpe:2.3:a:jenkins:pmd:3.45
  • Jenkins » Pmd » Version: 3.46
    cpe:2.3:a:jenkins:pmd:3.46
  • Jenkins » Pmd » Version: 3.47
    cpe:2.3:a:jenkins:pmd:3.47
  • Jenkins » Pmd » Version: 3.48
    cpe:2.3:a:jenkins:pmd:3.48
  • Jenkins » Pmd » Version: 3.49
    cpe:2.3:a:jenkins:pmd:3.49
  • Jenkins » Pmd » Version: 3.5
    cpe:2.3:a:jenkins:pmd:3.5
  • Jenkins » Pmd » Version: 3.6
    cpe:2.3:a:jenkins:pmd:3.6
  • Jenkins » Pmd » Version: 3.7
    cpe:2.3:a:jenkins:pmd:3.7
  • Jenkins » Pmd » Version: 3.8
    cpe:2.3:a:jenkins:pmd:3.8
  • Jenkins » Pmd » Version: 3.9
    cpe:2.3:a:jenkins:pmd:3.9


Contact Us

Shodan ® - All rights reserved