Vulnerability GHSA-2q27-6p2h-q6r3

High Risk
HIGH RISK
CVSS Score: 7.1
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 24, 2026 at 03:31 PM UTC
Jenkins Assembla Plugin has an XXE vulnerability
1.2.0 - 1.4.0
1.2.0 - 1.4.0

Summary

Jenkins Assembla Plugin has an XXE vulnerability

Details

Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when parsing responses from the configured Assembla server.

This allows attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery.

As of publication of this advisory, there is no fix.

Timeline

Published
3 months ago
June 24, 2026 at 03:31 PM UTC
Last Modified
2 days ago
September 25, 2026 at 08:00 PM UTC