CVE-2019-10466 is an XML External Entities (XXE) vulnerability in the Jenkins 360 FireLine Plugin, affecting installations with this plugin. It carries a high severity CVSS score of 8.1, indicating that an attacker with Overall/Read access can exploit it to extract secrets, perform server-side request forgery, or launch denial-of-service attacks. While the vulnerability is significant, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.2CPE matchmatch criteria | cpe:2.3:a:jenkins:360_fireline:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.