CVE-2021-43576: Jenkins POM2CONFIG

Medium severity, CVSS 6.5. EPSS: 2.4% chance of exploitation in the next 30 days.

Jenkins pom2config Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers with Overall/Read and Item/Read permissions to have Jenkins parse a crafted XML file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.

Affected products

  • Jenkins POM2CONFIG: up to and including 1.2

Published 2021-11-12. Last modified 2026-06-17.