[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2020-2305":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":14,"downstream":15,"duplicates":24,"related":25,"reserved_at":9,"published_at":26,"modified_at":27,"state":28,"summary":29,"references_raw":38,"kevs":66,"epss":67,"epss_history":70,"metrics":328,"affected":341},"CVE-2020-2305","Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.",null,[],[],[13],"GHSA-x58r-wxc3-7pqr",[],[16,18,20,22],{"_key":17},"RHSA-2021:0282",{"_key":19},"RHSA-2021:0637",{"_key":21},"RHSA-2021:0034",{"_key":23},"RHSA-2021:0038",[],[],"2020-11-04T14:35:39.000Z","2024-08-04T07:09:53.308Z","Modified",{"cisa_kev":30,"cisa_ransomware":30,"cisa_vendor":9,"epss_severity":31,"epss_score":32,"severity":33,"severity_score":34,"severity_version":35,"severity_source":36,"severity_vector":37,"severity_status":28},false,"low",0.00503,"medium",6.5,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",[39,48,53,57,61],{"url":40,"sources":41,"tags":44},"https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-2115",[42,36,43],"cve.org","osv_maven",[45,46,47],"X Refsource CONFIRM","Vendor Advisory","WEB",{"url":49,"sources":50,"tags":51},"https://nvd.nist.gov/vuln/detail/CVE-2020-2305",[43],[52],"Advisory",{"url":54,"sources":55,"tags":56},"https://github.com/jenkinsci/mercurial-plugin/commit/84af58b08f80bb92792f7bc04a31487f3eeee95a",[43],[47],{"url":58,"sources":59,"tags":60},"https://github.com/CVEProject/cvelist/blob/381fe967666a5ce01625a7a050427aa4757e3ca6/2020/2xxx/CVE-2020-2305.json",[43],[47],{"url":62,"sources":63,"tags":64},"https://github.com/jenkinsci/mercurial-plugin",[43],[65],"PACKAGE",[],{"date":68,"score":32,"percentile":69},"2026-06-04",0.66473,[71,74,77,80,83,86,88,91,94,97,100,103,106,108,110,113,116,119,121,124,127,130,133,135,138,141,143,146,149,152,155,158,161,164,167,169,172,175,178,181,184,186,188,191,194,197,200,203,206,209,212,215,218,221,224,226,229,231,234,237,240,243,245,248,251,254,257,260,263,266,269,272,274,277,280,283,286,289,292,295,298,301,304,307,310,313,316,319,322,325],{"date":72,"score":32,"percentile":73},"2025-11-04",0.65242,{"date":75,"score":32,"percentile":76},"2025-11-05",0.65221,{"date":78,"score":32,"percentile":79},"2025-11-06",0.65217,{"date":81,"score":32,"percentile":82},"2025-11-07",0.65228,{"date":84,"score":32,"percentile":85},"2025-11-08",0.65227,{"date":87,"score":32,"percentile":79},"2025-11-09",{"date":89,"score":32,"percentile":90},"2025-11-10",0.6521,{"date":92,"score":32,"percentile":93},"2025-11-11",0.6522,{"date":95,"score":32,"percentile":96},"2025-11-12",0.65243,{"date":98,"score":32,"percentile":99},"2025-11-13",0.65251,{"date":101,"score":32,"percentile":102},"2025-11-14",0.65258,{"date":104,"score":32,"percentile":105},"2025-11-15",0.65254,{"date":107,"score":32,"percentile":96},"2025-11-16",{"date":109,"score":32,"percentile":73},"2025-11-17",{"date":111,"score":32,"percentile":112},"2025-11-18",0.63473,{"date":114,"score":32,"percentile":115},"2025-11-19",0.63486,{"date":117,"score":32,"percentile":118},"2025-11-20",0.63487,{"date":120,"score":32,"percentile":102},"2025-11-21",{"date":122,"score":32,"percentile":123},"2025-11-22",0.65263,{"date":125,"score":32,"percentile":126},"2025-11-23",0.6525,{"date":128,"score":32,"percentile":129},"2025-11-24",0.65236,{"date":131,"score":32,"percentile":132},"2025-11-25",0.65239,{"date":134,"score":32,"percentile":73},"2025-11-26",{"date":136,"score":32,"percentile":137},"2025-11-27",0.65248,{"date":139,"score":32,"percentile":140},"2025-11-28",0.65234,{"date":142,"score":32,"percentile":90},"2025-11-29",{"date":144,"score":32,"percentile":145},"2025-11-30",0.65205,{"date":147,"score":32,"percentile":148},"2025-12-01",0.65361,{"date":150,"score":32,"percentile":151},"2025-12-02",0.65378,{"date":153,"score":32,"percentile":154},"2025-12-03",0.65376,{"date":156,"score":32,"percentile":157},"2025-12-04",0.65208,{"date":159,"score":32,"percentile":160},"2025-12-05",0.65223,{"date":162,"score":32,"percentile":163},"2025-12-06",0.65225,{"date":165,"score":32,"percentile":166},"2025-12-07",0.65224,{"date":168,"score":32,"percentile":82},"2025-12-08",{"date":170,"score":32,"percentile":171},"2025-12-09",0.65259,{"date":173,"score":32,"percentile":174},"2025-12-10",0.65307,{"date":176,"score":32,"percentile":177},"2025-12-11",0.65326,{"date":179,"score":32,"percentile":180},"2025-12-12",0.65346,{"date":182,"score":32,"percentile":183},"2025-12-13",0.6535,{"date":185,"score":32,"percentile":183},"2025-12-14",{"date":187,"score":32,"percentile":180},"2025-12-15",{"date":189,"score":32,"percentile":190},"2025-12-16",0.6536,{"date":192,"score":32,"percentile":193},"2025-12-17",0.65373,{"date":195,"score":32,"percentile":196},"2025-12-18",0.65412,{"date":198,"score":32,"percentile":199},"2025-12-19",0.65426,{"date":201,"score":32,"percentile":202},"2025-12-20",0.65424,{"date":204,"score":32,"percentile":205},"2025-12-21",0.65416,{"date":207,"score":32,"percentile":208},"2025-12-22",0.65409,{"date":210,"score":32,"percentile":211},"2025-12-23",0.6541,{"date":213,"score":32,"percentile":214},"2025-12-24",0.65417,{"date":216,"score":32,"percentile":217},"2025-12-25",0.65443,{"date":219,"score":32,"percentile":220},"2025-12-26",0.65441,{"date":222,"score":32,"percentile":223},"2025-12-27",0.65488,{"date":225,"score":32,"percentile":205},"2025-12-28",{"date":227,"score":32,"percentile":228},"2025-12-29",0.65408,{"date":230,"score":32,"percentile":202},"2025-12-30",{"date":232,"score":32,"percentile":233},"2025-12-31",0.65448,{"date":235,"score":32,"percentile":236},"2026-01-01",0.6563,{"date":238,"score":32,"percentile":239},"2026-01-02",0.65616,{"date":241,"score":32,"percentile":242},"2026-01-03",0.65617,{"date":244,"score":32,"percentile":233},"2026-01-04",{"date":246,"score":32,"percentile":247},"2026-01-05",0.65434,{"date":249,"score":32,"percentile":250},"2026-01-06",0.65444,{"date":252,"score":32,"percentile":253},"2026-01-07",0.65464,{"date":255,"score":32,"percentile":256},"2026-01-08",0.65481,{"date":258,"score":32,"percentile":259},"2026-01-09",0.65485,{"date":261,"score":32,"percentile":262},"2026-01-10",0.65483,{"date":264,"score":32,"percentile":265},"2026-01-11",0.65471,{"date":267,"score":32,"percentile":268},"2026-01-12",0.65456,{"date":270,"score":32,"percentile":271},"2026-01-13",0.65453,{"date":273,"score":32,"percentile":223},"2026-01-14",{"date":275,"score":32,"percentile":276},"2026-01-15",0.65509,{"date":278,"score":32,"percentile":279},"2026-01-16",0.65526,{"date":281,"score":32,"percentile":282},"2026-01-17",0.65512,{"date":284,"score":32,"percentile":285},"2026-01-18",0.65494,{"date":287,"score":32,"percentile":288},"2026-01-19",0.65482,{"date":290,"score":32,"percentile":291},"2026-01-20",0.65496,{"date":293,"score":32,"percentile":294},"2026-01-21",0.65507,{"date":296,"score":32,"percentile":297},"2026-01-22",0.65516,{"date":299,"score":32,"percentile":300},"2026-01-23",0.65549,{"date":302,"score":32,"percentile":303},"2026-01-24",0.65556,{"date":305,"score":32,"percentile":306},"2026-01-25",0.65524,{"date":308,"score":32,"percentile":309},"2026-01-26",0.65514,{"date":311,"score":32,"percentile":312},"2026-01-27",0.65523,{"date":314,"score":32,"percentile":315},"2026-01-28",0.65536,{"date":317,"score":32,"percentile":318},"2026-01-29",0.65537,{"date":320,"score":32,"percentile":321},"2026-01-30",0.65545,{"date":323,"score":32,"percentile":324},"2026-01-31",0.65548,{"date":326,"score":32,"percentile":327},"2026-02-01",0.65695,[329,339],{"source":36,"cvss_v2_0":330,"cvss_v3_0":9,"cvss_v3_1":335,"cvss_v4_0":9},{"baseScore":331,"baseSeverity":9,"vectorString":332,"impactScore":333,"exploitabilityScore":334},4,"AV:N/AC:L/Au:S/C:P/I:N/A:N",2.9,8,{"baseScore":34,"baseSeverity":336,"vectorString":37,"impactScore":337,"exploitabilityScore":338},"MEDIUM",6,7.2,{"source":43,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":340,"cvss_v4_0":9},{"baseScore":34,"baseSeverity":9,"vectorString":37,"impactScore":337,"exploitabilityScore":338},[342,354,361],{"ecosystem":9,"name":343,"vendor":344,"product":345,"cpe_part":346,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":347},"Jenkins Mercurial Plugin","jenkins project","jenkins mercurial plugin","a",[348],{"version":349,"is_range":350,"range_type":42,"version_start":351,"version_start_type":352,"version_end":353,"version_end_type":352,"fixed_in":9},">= unspecified, \u003C= 2.11",true,"unspecified","including","2.11",{"ecosystem":9,"name":355,"vendor":356,"product":355,"cpe_part":346,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":357},"mercurial","jenkins",[358],{"version":359,"is_range":350,"range_type":360,"version_start":9,"version_start_type":9,"version_end":353,"version_end_type":352,"fixed_in":9},"lte2.11","cpe",{"ecosystem":362,"name":363,"vendor":364,"product":355,"cpe_part":9,"purl_type":365,"purl_namespace":364,"purl_name":355,"source":9,"versions":366},"Maven","org.jenkins-ci.plugins:mercurial","org.jenkins-ci.plugins","maven",[367,372,376,380],{"version":368,"is_range":350,"range_type":369,"version_start":353,"version_start_type":352,"version_end":370,"version_end_type":371,"fixed_in":9},"gte2_11_lt2_12","ecosystem","2.12","excluding",{"version":373,"is_range":350,"range_type":369,"version_start":374,"version_start_type":352,"version_end":375,"version_end_type":371,"fixed_in":9},"gte2_10_lt2_10_1","2.10","2.10.1",{"version":377,"is_range":350,"range_type":369,"version_start":378,"version_start_type":352,"version_end":379,"version_end_type":371,"fixed_in":9},"gte2_9_lt2_9_1","2.9","2.9.1",{"version":381,"is_range":350,"range_type":369,"version_start":9,"version_start_type":9,"version_end":382,"version_end_type":371,"fixed_in":9},"lt2_8_1","2.8.1"]