CVE-2025-64134

HIGH

Jenkins JDepend Plugin < 1.3.1 - XML External Entity Injection

Title source: llm
STIX 2.1

Description

Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2025/10/29/2

Scores

CVSS v3 7.1
EPSS 0.0029
EPSS Percentile 20.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-611
Status published
Products (2)
jenkins/jdepend < 1.3.1
org.jenkins-ci.plugins/jdepend 0Maven
Published Oct 29, 2025
Tracked Since Feb 18, 2026