CVE-2015-8031

CRITICAL

Hudson <3.3.2 - XML External Entity Injection

Title source: llm
STIX 2.1

Description

Hudson (aka org.jvnet.hudson.main:hudson-core) before 3.3.2 allows XXE attacks.

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://security.snyk.io/vuln/SNYK-JAVA-ORGJVNETHUDSONMAIN-31221
Exploit, Third Party Advisory x_refsource_misc
https://github.com/advisories/GHSA-j3h2-8mf8-j5r2

Scores

CVSS v3 9.8
EPSS 0.0061
EPSS Percentile 70.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-611
Status published
Products (2)
eclipse/hudson < 3.2.2
org.jvnet.hudson.main/hudson-core 0 - 3.3.2Maven
Published Jul 18, 2022
Tracked Since Feb 18, 2026