CVE-2020-2172

MEDIUM

Jenkins Code Coverage API < 1.1.4 - XML Entity Expansion

Title source: rule
STIX 2.1

Description

Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Scores

CVSS v3 6.5
EPSS 0.0015
EPSS Percentile 35.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-776
Status published
Products (2)
io.jenkins.plugins/code-coverage-api 0 - 1.1.5Maven
jenkins/code_coverage_api < 1.1.4
Published Apr 07, 2020
Tracked Since Feb 18, 2026