CVE-2025-64134

HIGH

Jenkins Jdepend < 1.3.1 - XXE

Title source: rule
STIX 2.1

Description

Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.

Scores

CVSS v3 7.1
EPSS 0.0003
EPSS Percentile 7.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-611
Status published
Products (2)
jenkins/jdepend < 1.3.1
org.jenkins-ci.plugins/jdepend 0Maven
Published Oct 29, 2025
Tracked Since Feb 18, 2026