-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:generic-webhook-trigger | maven | <= 1.72 | 1.74 |
The vulnerability stems from insecure XML parsing in the XPath processing function. The commit diff shows the fix added 'factory.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)' to disable DTD processing. This indicates the vulnerable code path was in XML parsing logic handling webhook payloads, specifically in the XPath resolver that lacked proper XXE protections prior to the patch.
Ongoing coverage of React2Shell