vulnerability

Red Hat OpenShift: CVE-2019-10337: jenkins-plugin-token-macro: XML External Entity processing the ${XML} macro

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Jun 11, 2019
Added
Jul 4, 2019
Modified
Aug 11, 2025

Description

An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks.

Solutions

linuxrpm-upgrade-atomic-openshiftlinuxrpm-upgrade-jenkins-2-plugins
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.