Rapid7

vulnerability

Red Hat OpenShift: CVE-2019-10337: jenkins-plugin-token-macro: XML External Entity processing the ${XML} macro

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Jun 11, 2019
Added
Jul 4, 2019
Modified
Mar 30, 2026

Description

An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks.

Solutions

linuxrpm-upgrade-atomic-openshiftlinuxrpm-upgrade-jenkins-2-plugins
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.