CVE-2015-1809

HIGH

CloudBees Jenkins < 1.600 and LTS < 1.596.1 - XML External Entity Injection via XPath Query

Title source: llm
STIX 2.1

Description

XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query.

References (2)

Core 2
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1205625
Vendor Advisory x_refsource_misc
https://jenkins.io/security/advisory/2015-02-27/

Scores

CVSS v3 7.5
EPSS 0.0013
EPSS Percentile 32.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-611
Status published
Products (3)
jenkins/cloudbees < 1.596.1
jenkins/cloudbees < 1.600
org.jenkins-ci.main/jenkins-core 1.597 - 1.600Maven
Published Jan 15, 2020
Tracked Since Feb 18, 2026