org.jenkins-ci.plugins:token-macro
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.jenkins-ci.plugins:token-macropage 1 of 1
- CVE-2019-1003011HIGHCVSS 8.1EG 8.1✓ Fixed in 2.62019-02-06
vulnerable: 1.0 ... 2.5 (24 versions)
An information exposure and denial of service vulnerability exists in Jenkins Token Macro Plugin 2.5 and earlier in src/main/java/org/jenkinsci/plugins/tokenmacro/Parser.java, src/main/java/org/jenkinsci/plugins/tokenmacro/TokenMacro.java,…
- CVE-2019-10337HIGHCVSS 7.5EG 7.5✓ Fixed in 2.82019-06-11
vulnerable: 1.0 ... 2.7 (26 versions)
An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the ex…
Check whether org.jenkins-ci.plugins:token-macro is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.jenkins-ci.plugins:token-macro CVEs against the assets you own.
Start Free Scan →