CVE-2025-64134

Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:jdepend:*:*:*:*:*:jenkins:*:*

History

No history.

Information

Published : 2025-10-29 14:15

Updated : 2025-11-05 17:35


NVD link : CVE-2025-64134

Mitre link : CVE-2025-64134

CVE.ORG link : CVE-2025-64134


JSON object : View

Products Affected

jenkins

  • jdepend
CWE
CWE-611

Improper Restriction of XML External Entity Reference