Back to search
CVE-2025-64134
Published: Oct 29, 2025
Modified: Nov 4, 2025
PUBLISHED
Description
Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.
| Vendor | Product | Versions |
|---|---|---|
Jenkins Project | Jenkins JDepend Plugin | affected 0 - <= 1.3.1 |
References
Jenkins Security Advisory 2025-10-29
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now