GHSA-882r-r8fw-p538
GitHub Security Advisory
XXE vulnerability in Jenkins Job Import Plugin
✓ GitHub Reviewed
CRITICAL
Has CVE
Advisory Details
An XML external entity (XXE) processing vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport/client/RestApiClient.java that allows attackers with the ability to control the HTTP server (Jenkins) queried in preparation of job import to read arbitrary files, perform a denial of service attack, etc.
Affected Packages
Maven
org.jenkins-ci.plugins:job-import-plugin
Affected versions:
0
(fixed in 3.0)
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: July 6, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.