CVE 7.1 HIGH

CVE-2026-57303_CVE-2026-57303

7.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Description

Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery.

Basic Information

ID CVE-2026-57303
Source jenkins
Published Jun 24, 2026 at 13:20
Modified Jun 24, 2026 at 14:19

Affected Product

Vendor Jenkins Project
Product Jenkins Assembla Plugin
Affected Versions Jenkins Project Jenkins Assembla Plugin 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.