GHSA-g6h2-4x64-c59x
GitHub Security Advisory
Improper Restriction of XML External Entity Reference Jenkins Token Macro Plugin
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks.
Affected Packages
Maven
org.jenkins-ci.plugins:token-macro
Affected versions:
0
(fixed in 2.8)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.