cbcvebase.
CVE-2019-16549
published 2019-12-17

CVE-2019-16549: Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks, allowing man-in-the-middle…

high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks, allowing man-in-the-middle attackers to have Jenkins parse crafted XML documents.

Affected

21 ranges
VendorProductVersion rangeFixed in
jenkinsalauda_devops_pipeline_plugin
jenkinsalauda_kubernetes_suport_plugin
jenkinsbuild_failure_analyzer_plugin
jenkinsgerrit_trigger_plugin
jenkinsids_in_team_concert_plugin
jenkinsids_to_allow_users_configuring_the_plugin
jenkinsjenkins_and_plugin
jenkinsmantis_plugin
jenkinsmaven<= 0.16.1
jenkinsmaven_release_plug-in_plugin
jenkinsmission_control_plugin
jenkinspipeline_aggregator_view_plugin
jenkinsrapiddeploy_plugin
jenkinsredgate_sql_change_automation_plugin
jenkinsrundeck_plugin
jenkinssctmexecutor_plugin
jenkinsspira_importer_plugin
jenkinsteam_concert_plugin
jenkinswebsphere_deployer_plugin
jenkinsweibo_plugin
jenkins_projectjenkins_maven_release_pluginunspecified – 0.16.1