#VU23665 XML External Entity injection in Maven Release - CVE-2019-16549
Published: December 18, 2019
Maven Release
Jenkins
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied XML input. A remote authenticated attacker can pass a specially crafted XML code to the affected application, conduct a man-in-the-middle attack and have Jenkins parse crafted XML documents.