Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2019-10782

Disclosure Date: January 30, 2020 (last updated February 21, 2025)
All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.
Attacker Value
Unknown

CVE-2019-9658

Disclosure Date: March 11, 2019 (last updated November 08, 2023)
Checkstyle before 8.18 loads external DTDs by default.
0
Attacker Value
Unknown

CVE-2018-1000009

Disclosure Date: January 23, 2018 (last updated November 26, 2024)
Jenkins Checkstyle Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.
0