Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-6147

19
FAUCET Score

CVE-2023-6147 is a missing permission check vulnerability in the Qualys Jenkins Plugin for Policy Compliance (versions 1.0.5 and earlier). This flaw allows any authenticated user with job configuration privileges to inject XML External Entity (XXE) payloads by configuring a rogue endpoint during a connectivity check to Qualys Cloud Services. The vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity, requiring low privileges, and potentially leading to high impact on integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. Community discussion and media coverage are minimal, suggesting low current attention.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.0.5CPE matchmatch criteria
cpe:2.3:a:qualys:policy_compliance:*:*:*:*:*:jenkins:*:*

CVSS Data

CVSS version used by this source: 3.1

5.7MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.1
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.55%
Probability of exploitation in next 30 days
EPSS Percentile
42.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0055 is in the 53rd percentile among its peer group of 21,954 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

mavenpatch availablevia ghsa
Product: com.qualys.plugins:qualys-pcFixed in: 1.0.6
pfsensepatch availablevia llm_extracted
View patch
gcpvendor investigatingvia llm_extracted
View patch
m2teamvendor investigatingvia llm_extracted
View patch
mozillavendor investigatingvia llm_extracted
nessusvendor investigatingvia llm_extracted
View patch
netgearvendor investigatingvia llm_extracted
View patch

Vendor Advisories (7)

netgearllm-netgear-6c61e76d3d0d5f87

Possible XXE vulnerability in Jenkins Plugin for Qualys Policy Compliance

Jan 10, 2024
pfsensellm-pfsense-2f7924742b5d2232

Possible XXE vulnerability in Jenkins Plugin for Qualys Policy Compliance

Jan 10, 2024
mozillallm-mozilla-7ff89b7228718ddc

Possible XXE vulnerability in Jenkins Plugin for Qualys Policy Compliance

Jan 10, 2024
nessusllm-nessus-09a808948984454a

Possible XXE vulnerability in Jenkins Plugin for Qualys Policy Compliance

Jan 10, 2024
m2teamllm-m2team-f0eacf2de444f89b

Possible XXE vulnerability in Jenkins Plugin for Qualys Policy Compliance

Jan 10, 2024
gcpllm-gcp-3c300bb8e4bbbfe0

Possible XXE vulnerability in Jenkins Plugin for Qualys Policy Compliance

Jan 10, 2024
mavenGHSA-8525-52vg-jv6vmedium

Qualys Jenkins Plugin for Policy Compliance XML External Entity vulnerability

Jan 9, 2024

References

qualys.com / security-advisories
Vendor Advisory
openwall.com / lists/oss-security/2024/01/24/6