Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.
| Software | From | Fixed in |
|---|---|---|
org.jenkins-ci.plugins / jdepend
|
- | 1.3.1.x |
| jenkins / jdepend | - | 1.3.1.x |