CVE-2025-64134
29.10.2025, 14:15
Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.Enginsight
| Vendor | Product | Version |
|---|---|---|
| jenkins | jdepend | 𝑥 ≤ 1.3.1 |
𝑥
= Vulnerable software versions