CVE-2019-10337: XEE

Published Jun 11, 2019
·
Updated

An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks.

Other sources

Token Macro Plugin did not configure its XML parser in a way that would prevent XML External Entity (XXE) processing. This allowed attackers able to control the contents of files processed with the ${XML} macro to have Jenkins parse a maliciously crafted XML file that uses external entities for extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks. Token Macro Plugin no longer processes XML External Entities in XML documents.

References:

https://jenkins.io/security/advisory/2019-06-11/

Red Hat

Affected Software

6 affected componentsFixes available
redhat/atomic-openshift<0:3.11.129-1.git.0.bd4f2d5.el7
0:3.11.129-1.git.0.bd4f2d5.el7
redhat/jenkins<2-plugins-0:3.11.1560870549-1.el7
2-plugins-0:3.11.1560870549-1.el7
redhat/jenkins<2-plugins-0:4.1.1561471763-1.el7
2-plugins-0:4.1.1561471763-1.el7
redhat/jenkins-plugin-token-macro<2.8
2.8
maven/org.jenkins-ci.plugins:token-macro<=2.7
2.8
Jenkins Token Macro Jenkins<=2.7

Event History

Jun 11, 2019
CVE Published
12:00 AM
CVE Published
via MITRE·01:15 PM
Data Sourced
via MITRE·01:15 PM
Description
May 24, 2022
Advisory Published
via GitHub·04:47 PM

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2019-10337?

CVE-2019-10337 is considered a high severity vulnerability due to its potential to expose sensitive information through XML external entity processing.

2

How do I fix CVE-2019-10337?

To fix CVE-2019-10337, update the Jenkins Token Macro Plugin to version 2.8 or later.

3

What impact does CVE-2019-10337 have on my Jenkins environment?

CVE-2019-10337 can allow attackers to read sensitive files from the server and extract secrets from the Jenkins agent.

4

Which software versions are vulnerable to CVE-2019-10337?

Versions of the Jenkins Token Macro Plugin prior to 2.8 are vulnerable to CVE-2019-10337.

5

Who is affected by CVE-2019-10337?

Any users of the Jenkins Token Macro Plugin versions 2.7 and earlier are affected by CVE-2019-10337.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203