CVE-2025-64134

Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:jdepend:*:*:*:*:*:jenkins:*:*

History

05 Nov 2025, 17:35

Type Values Removed Values Added
First Time Jenkins
Jenkins jdepend
CPE cpe:2.3:a:jenkins:jdepend:*:*:*:*:*:jenkins:*:*
References () https://www.jenkins.io/security/advisory/2025-10-29/#SECURITY-2936 - () https://www.jenkins.io/security/advisory/2025-10-29/#SECURITY-2936 - Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2025/10/29/2 - () http://www.openwall.com/lists/oss-security/2025/10/29/2 - Mailing List, Third Party Advisory

04 Nov 2025, 22:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/10/29/2 -

29 Oct 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-29 14:15

Updated : 2025-11-05 17:35


NVD link : CVE-2025-64134

Mitre link : CVE-2025-64134

CVE.ORG link : CVE-2025-64134


JSON object : View

Products Affected

jenkins

  • jdepend
CWE
CWE-611

Improper Restriction of XML External Entity Reference