PT-2020-10391 · Mojohaus · Mojohaus Exec Maven Plugin

Published

2020-01-06

·

Updated

2020-01-15

·

CVE-2019-20343

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The MojoHaus Exec Maven plugin version 1.1.1
Description The issue allows code execution via a crafted XML document. This is possible because a configuration element, within a plugin element, can specify an arbitrary program in an executable element and can also specify arbitrary command-line arguments in an arguments element.
Recommendations For The MojoHaus Exec Maven plugin version 1.1.1, consider restricting the use of the executable element and arguments element within the plugin configuration to minimize the risk of exploitation.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20343

Affected Products

Mojohaus Exec Maven Plugin