CVE-2020-2092: Jenkins Robot Framework

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing users with Job/Configure to have Jenkins parse crafted XML documents.

Affected products

  • Jenkins Robot Framework: up to and including 2.0.0

Published 2020-01-15. Last modified 2026-06-17.