CVE-2023-37942: Jenkins External Monitor Job Type

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Jenkins External Monitor Job Type Plugin 206.v9a_94ff0b_4a_10 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Affected products

  • Jenkins External Monitor Job Type: up to and including 206.v9a_94ff0b_4a_10

Published 2023-07-12. Last modified 2026-06-17.