Jenkins Maven vulnerabilities
6 known vulnerabilities affecting jenkins/maven.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2021-26291CRITICALCVSS 9.1≥ 0, < 3.8.6-12021-04-23
CVE-2021-26291 [CRITICAL] CVE-2021-26291: Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting i
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is c
osv
CVE-2019-16549HIGHCVSS 8.1≤ 0.16.12019-12-17
CVE-2019-16549 [HIGH] CWE-611 CVE-2019-16549: Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML ext
Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks, allowing man-in-the-middle attackers to have Jenkins parse crafted XML documents.
nvd
CVE-2019-16550HIGHCVSS 8.8≤ 0.16.12019-12-17
CVE-2019-16550 [HIGH] CWE-352 CVE-2019-16550: A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release
A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release Plugin 0.16.1 and earlier allows attackers to have Jenkins connect to an attacker specified web server and parse XML documents.
nvd
CVE-2019-10358MEDIUMCVSS 6.5≤ 3.32019-07-31
CVE-2019-10358 [MEDIUM] CWE-532 CVE-2019-10358: Jenkins Maven Integration Plugin 3.3 and earlier did not apply build log decorators to module builds
Jenkins Maven Integration Plugin 3.3 and earlier did not apply build log decorators to module builds, potentially revealing sensitive build variables in the build log.
nvd
CVE-2017-1000397MEDIUMCVSS 5.9≤ 2.172018-01-26
CVE-2017-1000397 [MEDIUM] CVE-2017-1000397: Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the v
Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on commons-httpclient.
nvd
CVE-2013-0253MEDIUMCVSS 5.8≥ 0, < 3.0.5-12013-04-09
CVE-2013-0253 [MEDIUM] CVE-2013-0253: The default configuration of Apache Maven 3
The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.
osv