7.1
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Description
Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery.
Basic Information
ID
CVE-2026-57303
Source
jenkins
Published
Jun 24, 2026 at 13:20
Modified
Jun 24, 2026 at 14:19
Affected Product
Vendor
Jenkins Project
Product
Jenkins Assembla Plugin
Affected Versions
Jenkins Project Jenkins Assembla Plugin 0