Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 24 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Jenkins Assembla Plugin XXE Vulnerability Allows Secret Extraction |
Wed, 24 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins Project
Jenkins Project jenkins Assembla Plugin |
|
| Vendors & Products |
Jenkins Project
Jenkins Project jenkins Assembla Plugin |
Wed, 24 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XML External Entity Vulnerability in Jenkins Assembla Plugin Enables Secrets Exposure | |
| Weaknesses | CWE-611 |
Wed, 24 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XML External Entity Vulnerability in Jenkins Assembla Plugin Enables Secrets Exposure | |
| Weaknesses | CWE-611 |
Wed, 24 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-918 | |
| Metrics |
cvssV3_1
|
Wed, 24 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-06-24T14:19:33.790Z
Reserved: 2026-06-24T08:41:44.359Z
Link: CVE-2026-57303
Updated: 2026-06-24T14:17:24.201Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T21:30:04Z