org.jenkins-ci.plugins:mercurial
Maven7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.jenkins-ci.plugins:mercurialpage 1 of 1
- CVE-2018-1000112MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.32018-03-13
vulnerable: 1.37 ... 2.2 (39 versions)
An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and earlier in MercurialStatus.java that allows an attacker with network access to obtain a list of nodes and users.
- CVE-2020-2305MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.8.12020-11-04
vulnerable: 1.37 ... 2.8 (45 versions)
Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2020-2306MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.8.12020-11-04
vulnerable: 1.37 ... 2.8 (45 versions)
A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations.
- CVE-2022-30947HIGHCVSS 7.5EG 7.5✓ Fixed in 2.16.12022-05-17
vulnerable: 1.37 ... 2.9.1 (58 versions)
Jenkins Git Plugin 4.11.1 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other p…
- CVE-2022-30948HIGHCVSS 7.5EG 7.5✓ Fixed in 2.16.12022-05-17
vulnerable: 1.37 ... 2.9.1 (58 versions)
Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about oth…
- CVE-2022-30949MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.16.12022-05-17
vulnerable: 1.37 ... 2.9.1 (58 versions)
Jenkins REPO Plugin 1.14.0 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other …
- CVE-2022-43410MEDIUMCVSS 5.3EG 5.3✓ Fixed in 1260.vdfb_723cdcc812022-10-19
vulnerable: 1.37 ... 2.9.1 (61 versions)
Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its webhook endpoint, including jobs the user has no permission to access.
Check whether org.jenkins-ci.plugins:mercurial is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.jenkins-ci.plugins:mercurial CVEs against the assets you own.
Start Free Scan →