Vulnerability GHSA-2q27-6p2h-q6r3
High Risk
HIGH RISK
CVSS Score: 7.1
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 24, 2026 at 03:31 PM UTC
Jenkins Assembla Plugin has an XXE vulnerability
1.2.0 - 1.4.0
1.2.0 - 1.4.0
Summary
Jenkins Assembla Plugin has an XXE vulnerability
Details
Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when parsing responses from the configured Assembla server.
This allows attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery.
As of publication of this advisory, there is no fix.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
3 months ago
Jenkins Assembla Plugin has a missing permission check
1.2.0 - 1.4.0 GHSA-2r5w-jh6g-8hff
1.2.0 - 1.4.0 GHSA-2r5w-jh6g-8hff
Medium Risk
3 months ago
Jenkins Assembla Plugin has a cross-site request forgery (CSRF) vulnerability
1.2.0 - 1.4.0 GHSA-429r-3j78-2pxm
1.2.0 - 1.4.0 GHSA-429r-3j78-2pxm
Low Risk
4 years ago
Jenkins Assembla Plugin has Insufficiently Protected Credentials
1.2.0 - 1.4.0 GHSA-mhq6-h9m7-wq8c
1.2.0 - 1.4.0 GHSA-mhq6-h9m7-wq8c
Impacted packages
Timeline
Published
3 months ago
June 24, 2026 at 03:31 PM UTC
Last Modified
2 days ago
September 25, 2026 at 08:00 PM UTC