CVE-2025-64134

Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.
Configurations

No configuration.

History

29 Oct 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-29 14:15

Updated : 2025-10-30 15:03


NVD link : CVE-2025-64134

Mitre link : CVE-2025-64134

CVE.ORG link : CVE-2025-64134


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference