CVE-2025-64134EPSS p27.1%
CVE-2025-64134CVE-2025-64134
jenkins / jdepend
Description
Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.
Scoring
| CVSS | 7.1 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
| EPSS | 0.35% probability of exploitation · percentile 27.1% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-08 |