CVE-2019-20343
CRITICALMojoHaus Exec Maven Plugin 1.1.1 - Remote Code Execution via Crafted XML Configuration
Title source: llmDescription
The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executable element (and can also specify arbitrary command-line arguments in an arguments element).
References (3)
Core 3
Core References
Vendor Advisory x_refsource_misc
https://www.mojohaus.org/exec-maven-plugin/
Third Party Advisory x_refsource_misc
https://drive.google.com/open?id=0B5UvrSwn4wuwTnNqSzZESjIwZHo5ZXhWdHh2T2Z0eWRCT1hF
Third Party Advisory x_refsource_misc
https://drive.google.com/open?id=1GLs0d9IGArMVrlbEGbxgCjA1MuzIJk-3
Scores
CVSS v3
9.8
EPSS
0.0241
EPSS Percentile
82.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-94
Status
published
Products (1)
mojohaus/exec_maven
1.1.1
Published
Jan 06, 2020
Tracked Since
Feb 18, 2026