CVE-2015-1809: Jenkins Cloudbees

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query.

Affected products

  • Jenkins Cloudbees: before 1.596.1 (fixed in 1.596.1); before 1.600 (fixed in 1.600)

Published 2020-01-15. Last modified 2026-06-17.