Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2019-10782
Disclosure Date: January 30, 2020 (last updated February 21, 2025)
All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.
0
Attacker Value
Unknown
CVE-2019-9658
Disclosure Date: March 11, 2019 (last updated November 08, 2023)
Checkstyle before 8.18 loads external DTDs by default.
0
Attacker Value
Unknown
CVE-2018-1000009
Disclosure Date: January 23, 2018 (last updated November 26, 2024)
Jenkins Checkstyle Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.
0