{"id":"CVE-2019-10327","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-10327","summary":"XML External Entity processing vulnerability in Pipeline Maven Integration Jenkins Plugin","details":"An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed attackers able to control a temporary directory's content on the agent running the Maven build to have Jenkins parse a maliciously crafted XML file that uses external entities for extraction of secrets from the Jenkins master, server-side request forgery, or denial-of-service attacks.","published":"2022-05-24T22:00:03Z","modified":"2024-02-16T08:24:00.907016Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"},"epss":{"score":0.01399,"percentile":0.69989,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.jenkins-ci.plugins:pipeline-maven","fixedVersion":"3.7.1"}],"fix":{"url":"https://github.com/jenkinsci/pipeline-maven-plugin/commit/e7cb858852c05d2423e3fd9922a090982dcd6392","label":"jenkinsci/pipeline-maven-plugin@e7cb858"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10327"},{"type":"WEB","url":"https://github.com/jenkinsci/pipeline-maven-plugin/commit/e7cb858852c05d2423e3fd9922a090982dcd6392"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/pipeline-maven-plugin/tree/master/pipeline-maven"},{"type":"WEB","url":"https://jenkins.io/security/advisory/2019-05-31/#SECURITY-1409"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2019/05/31/2"},{"type":"WEB","url":"http://www.securityfocus.com/bid/108540"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-02-16T08:24:00.907016Z"}}