High severity7.5NVD Advisory· Published Jan 15, 2020· Updated Jun 17, 2026
CVE-2015-1811
CVE-2015-1811
Description
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via a crafted XML document.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.main:jenkins-coreMaven | >= 1.597, < 1.600 | 1.600 |
org.jenkins-ci.main:jenkins-coreMaven | < 1.596.1 | 1.596.1 |
Affected products
3before 1.600+ 1 more
- (no CPE)range: before 1.600
- (no CPE)range: before 1.596.1
Patches
Vulnerability mechanics
References
5- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-qg7x-4h4q-3m49ghsaADVISORY
- jenkins.io/security/advisory/2015-02-27/nvdVendor Advisory
- nvd.nist.gov/vuln/detail/CVE-2015-1811ghsaADVISORY
- jenkins.io/security/advisory/2015-02-27ghsaWEB
News mentions
0No linked articles in our index yet.