Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 30 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins jenkins |
|
| Vendors & Products |
Jenkins
Jenkins jenkins |
Thu, 30 Oct 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Oct 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-611 | |
| Metrics |
cvssV3_1
|
Wed, 29 Oct 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published: 2025-10-29T13:29:41.699Z
Updated: 2025-11-04T21:14:26.342Z
Reserved: 2025-10-28T07:34:37.541Z
Link: CVE-2025-64134
Updated: 2025-11-04T21:14:26.342Z
Status : Awaiting Analysis
Published: 2025-10-29T14:15:57.613
Modified: 2025-11-04T22:16:39.717
Link: CVE-2025-64134
No data.