org.jenkins-ci.plugins:mercurial
Maven7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.jenkins-ci.plugins:mercurialpage 1 of 1
- CVE-2018-1000112MEDIUMCVSS 5.3EG 5.3fixed in 2.32018-03-13
vulnerable: 1.37 ... 2.2 (39 versions)
An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and earlier in MercurialStatus.java that allows an attacker with network access to obtain a list of nodes and users.
- CVE-2020-2305MEDIUMCVSS 6.5EG 6.5fixed in 2.12, 2.10.1, 2.9.1 or 2.8.1, by version range2020-11-04
vulnerable: 1.37 ... 2.8 (45 versions)
Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2020-2306MEDIUMCVSS 4.3EG 4.3fixed in 2.12, 2.10.1, 2.9.1 or 2.8.1, by version range2020-11-04
vulnerable: 1.37 ... 2.8 (45 versions)
A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations.
- CVE-2022-30947HIGHCVSS 7.5EG 7.5fixed in 2.16.12022-05-17
vulnerable: 1.37 ... 2.9.1 (58 versions)
Jenkins Git Plugin 4.11.1 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other p…
- CVE-2022-30948HIGHCVSS 7.5EG 7.5fixed in 2.16.12022-05-17
vulnerable: 1.37 ... 2.9.1 (58 versions)
Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about oth…
- CVE-2022-30949MEDIUMCVSS 5.3EG 5.3fixed in 2.16.12022-05-17
vulnerable: 1.37 ... 2.9.1 (58 versions)
Jenkins REPO Plugin 1.14.0 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other …
- CVE-2022-43410MEDIUMCVSS 5.3EG 5.3fixed in 1260.vdfb_723cdcc812022-10-19
vulnerable: 1.37 ... 2.9.1 (61 versions)
Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its webhook endpoint, including jobs the user has no permission to access.
Check whether org.jenkins-ci.plugins:mercurial is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.jenkins-ci.plugins:mercurial CVEs against the assets you own.
Book a Demo →