5
CVSSv2

CVE-2019-10337

Published: 11/06/2019 Updated: 25/10/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and previous versions allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins token macro

Vendor Advisories

Synopsis Moderate: OpenShift Container Platform 311 security update Type/Severity Security Advisory: Moderate Topic An update for atomic-openshift and jenkins-2-plugins is now available forRed Hat OpenShift Container Platform 311Red Hat Product Security has rated this update as having a security impactof ...
Synopsis Important: OpenShift Container Platform 41 jenkins-2-plugins security update Type/Severity Security Advisory: Important Topic An update for jenkins-2-plugins is now available for Red Hat OpenShiftContainer Platform 41Red Hat Product Security has rated this update as having a security impactof Im ...
Impact: Moderate Public Date: 2019-06-11 CWE: CWE-611 Bugzilla: 1719782: CVE-2019-10337 jenkins-plugin- ...