9.8
CVSSv3

CVE-2019-20343

CVSSv4: NA | CVSSv3: 9.8 | CVSSv2: 7.5 | VMScore: 1000 | EPSS: 0.01124 | KEV: Not Included
Published: 06/01/2020 Updated: 21/11/2024

Vulnerability Summary

The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executable element (and can also specify arbitrary command-line arguments in an arguments element).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mojohaus exec maven 1.1.1