CVE-2019-10337
Estado: ModificadaAlta (7.5)—
An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.04%
- Percentil entre todas las CVEs puntuadas: 80
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-611
Referencias
- http://www.openwall.com/lists/oss-security/2019/06/11/1
- http://www.securityfocus.com/bid/108747
- https://access.redhat.com/errata/RHSA-2019:1636
- https://access.redhat.com/errata/RHSA-2019:1851
- https://jenkins.io/security/advisory/2019-06-11/#SECURITY-1399
- http://www.openwall.com/lists/oss-security/2019/06/11/1
- http://www.securityfocus.com/bid/108747
- https://access.redhat.com/errata/RHSA-2019:1636
- https://access.redhat.com/errata/RHSA-2019:1851
- https://jenkins.io/security/advisory/2019-06-11/#SECURITY-1399
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-10337",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "jenkinsci-cert@googlegroups.com",
"affectedData": [
{
"vendor": "Jenkins project",
"product": "Jenkins Token Macro Plugin",
"versions": [
{
"status": "affected",
"version": "2.7 and earlier"
}
]
}
]
}
],
"published": "2019-06-11T14:29:01.057",
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2019/06/11/1",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "jenkinsci-cert@googlegroups.com"
},
{
"url": "http://www.securityfocus.com/bid/108747",
"source": "jenkinsci-cert@googlegroups.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2019:1636",
"source": "jenkinsci-cert@googlegroups.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2019:1851",
"source": "jenkinsci-cert@googlegroups.com"
},
{
"url": "https://jenkins.io/security/advisory/2019-06-11/#SECURITY-1399",
"tags": [
"Vendor Advisory"
],
"source": "jenkinsci-cert@googlegroups.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2019/06/11/1",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/108747",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://access.redhat.com/errata/RHSA-2019:1636",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://access.redhat.com/errata/RHSA-2019:1851",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://jenkins.io/security/advisory/2019-06-11/#SECURITY-1399",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-611"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the \"XML\" macro to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks."
},
{
"lang": "es",
"value": "Una vulnerabilidad de entidades externas XML (XXE) en el Plugin Token Macro de Jenkins versión 2.7 y anteriores, permitía a los atacantes capaces de controlar el contenido del archivo de entrada de la macro \"XML\" para tener Jenkins que resolver las entidades externas, resultando en la extracción de secretos del agente de Jenkins, la falsificación de peticiones del lado del servidor o ataques de denegación de servicio."
}
],
"lastModified": "2026-06-17T02:10:44.563",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jenkins:token_macro:*:*:*:*:*:jenkins:*:*",
"vulnerable": true,
"matchCriteriaId": "46CF086E-57E0-4D08-AD1E-068DE509AFEF",
"versionEndIncluding": "2.7"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "jenkinsci-cert@googlegroups.com"
}