CVE-2019-16549

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
17/12/2019
Last modified:
25/10/2023

Description

Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks, allowing man-in-the-middle attackers to have Jenkins parse crafted XML documents.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:maven:*:*:*:*:*:jenkins:*:* 0.16.1 (including)