CVE-2025-64134

Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:jdepend:*:*:*:*:*:jenkins:*:*

History

05 Nov 2025, 17:35

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/10/29/2 - Mailing List, Third Party Advisory
References () https://www.jenkins.io/security/advisory/2025-10-29/#SECURITY-2936 - () https://www.jenkins.io/security/advisory/2025-10-29/#SECURITY-2936 - Vendor Advisory
CPE cpe:2.3:a:jenkins:jdepend:*:*:*:*:*:jenkins:*:*
First Time Jenkins
Jenkins jdepend

Information

Published : 2025-10-29 14:15

Updated : 2025-11-05 17:35


NVD link : CVE-2025-64134

Mitre link : CVE-2025-64134

CVE.ORG link : CVE-2025-64134


JSON object : View

Products Affected

jenkins

  • jdepend
CWE
CWE-611

Improper Restriction of XML External Entity Reference