XML External Entity Vulnerability in Jenkins Ivy Report Plugin
CVE-2026-70448
Currently unrated
What is CVE-2026-70448?
The Jenkins Ivy Report Plugin versions up to 1.2 are susceptible to an XML external entity (XXE) vulnerability, which arises from inadequate configuration of its XML parser. This oversight can lead to the processing of malicious Ivy report files, allowing attackers to exploit external entities and potentially expose sensitive data or cause unintended behavior within the application. Ensuring proper parser configuration is crucial to mitigating these risks and safeguarding your Jenkins environment.
Affected Version(s)
Jenkins Ivy Report Plugin 0 <= 1.2