Jenkins Token Macro vulnerabilities
2 known vulnerabilities affecting jenkins/token_macro.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2019-10337HIGHCVSS 7.5≤ 2.72019-06-11
CVE-2019-10337 [HIGH] CWE-611 CVE-2019-10337: An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed a
An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks.
nvd
CVE-2019-1003011HIGHCVSS 8.1≤ 2.52019-02-06
CVE-2019-1003011 [HIGH] CWE-674 CVE-2019-1003011: An information exposure and denial of service vulnerability exists in Jenkins Token Macro Plugin 2.5
An information exposure and denial of service vulnerability exists in Jenkins Token Macro Plugin 2.5 and earlier in src/main/java/org/jenkinsci/plugins/tokenmacro/Parser.java, src/main/java/org/jenkinsci/plugins/tokenmacro/TokenMacro.java, src/main/java/org/jenkinsci/plugins/tokenmacro/impl/AbstractChangesSinceMacro.java, src/main/java/org/jenkins
nvd