CVE-2022-41226: Jenkins Compuware Common Configuration

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Affected products

  • Jenkins Compuware Common Configuration: before 1.0.15 (fixed in 1.0.15)

Published 2022-09-21. Last modified 2026-06-17.