Skip to main content

Vendor/product archive

jenkins / maven CVEs

Beta · best-effort

4 CVEs tagged to jenkins / maven0 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2019-16550

Published Dec 17, 2019

A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release Plugin 0.16.1 and earlier allows attackers to have Jenkins connect to an attac…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16549

Published Dec 17, 2019

Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks, allowing man-in-the-middle attackers to have Jenkin…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10358

Published Jul 31, 2019

Jenkins Maven Integration Plugin 3.3 and earlier did not apply build log decorators to module builds, potentially revealing sensitive build variables in the build log.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000397

Published Jan 26, 2018

Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making i…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1