Jenkins Project Jenkins Maven Release Plugin vulnerabilities

5 known vulnerabilities affecting jenkins_project/jenkins_maven_release_plugin.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2019-16549HIGHCVSS 8.1≥ unspecified, ≤ 0.16.12019-12-17
CVE-2019-16549 [HIGH] CWE-611 CVE-2019-16549: Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML ext Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks, allowing man-in-the-middle attackers to have Jenkins parse crafted XML documents.
cvelistv5nvd
CVE-2019-16550HIGHCVSS 8.8≥ unspecified, ≤ 0.16.12019-12-17
CVE-2019-16550 [HIGH] CWE-352 CVE-2019-16550: A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release Plugin 0.16.1 and earlier allows attackers to have Jenkins connect to an attacker specified web server and parse XML documents.
cvelistv5nvd
CVE-2019-10361MEDIUMCVSS 5.5v0.14.0 and earlier2019-07-31
CVE-2019-10361 [MEDIUM] CWE-522 CVE-2019-10361: Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be viewed by users with access to the master file system.
cvelistv5nvd
CVE-2019-10359MEDIUMCVSS 6.3v0.14.0 and earlier2019-07-31
CVE-2019-10359 [MEDIUM] CWE-352 CVE-2019-10359: A cross-site request forgery vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier in the A cross-site request forgery vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier in the M2ReleaseAction#doSubmit method allowed attackers to perform releases with attacker-specified options.
cvelistv5nvd
CVE-2019-10360MEDIUMCVSS 5.4v0.14.0 and earlier2019-07-31
CVE-2019-10360 [MEDIUM] CWE-79 CVE-2019-10360: A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allow A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allowed attackers to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.
cvelistv5nvd