Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-05 18:17
Updated : 2026-08-31 19:34
NVD link : CVE-2026-70448
Mitre link : CVE-2026-70448
CVE.ORG link : CVE-2026-70448
JSON object : View
Products Affected
No product.
CWE
CWE-611
Improper Restriction of XML External Entity Reference
