Known Vulnerabilities for Maven by Jenkins
Listed below are 4 of the newest known vulnerabilities associated with "Maven" by "Jenkins".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-64609 json | Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint... | Not Provided | 2026-07-21 | 2026-07-21 |
| CVE-2026-13502 json | A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4... | Not Provided | 2026-06-28 | 2026-06-29 |
| CVE-2026-9563 json | In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum ... | Not Provided | 2026-07-02 | 2026-07-02 |
| CVE-2026-7860 json | A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the f... | Not Provided | 2026-05-19 | 2026-05-21 |
| CVE-2026-5952 json | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1... | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2024-23686 json | DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in d... | Not Provided | 2024-01-19 | 2026-07-14 |
| CVE-2019-16550 json | A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release Plugin 0.16.1 and earlie... | 8.8 - HIGH | 2019-12-17 | 2023-10-25 |
| CVE-2019-16549 json | Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attack... | 8.1 - HIGH | 2019-12-17 | 2023-10-25 |
| CVE-2019-10358 json | Jenkins Maven Integration Plugin 3.3 and earlier did not apply build log decorators to module builds, potentially revealing s... | 6.5 - MEDIUM | 2019-07-31 | 2023-10-25 |
| CVE-2017-1000397 json | Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-615... | 5.9 - MEDIUM | 2018-01-26 | 2018-02-08 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jenkins | Maven | 3.4 | |||
| Application | Jenkins | Maven | 3.3 | |||
| Application | Jenkins | Maven | 3.2 | |||
| Application | Jenkins | Maven | 3.1.2 | |||
| Application | Jenkins | Maven | 3.1.1 | |||
| Application | Jenkins | Maven | 3.1 | |||
| Application | Jenkins | Maven | 3.0 | |||
| Application | Jenkins | Maven | 2.9 | |||
| Application | Jenkins | Maven | 2.8 | |||
| Application | Jenkins | Maven | 2.7 | |||
| Application | Jenkins | Maven | 2.6 | |||
| Application | Jenkins | Maven | 2.5 | |||
| Application | Jenkins | Maven | 2.4 | |||
| Application | Jenkins | Maven | 2.3 | |||
| Application | Jenkins | Maven | 2.2 | |||
| Application | Jenkins | Maven | 2.17 | |||
| Application | Jenkins | Maven | 2.16 | |||
| Application | Jenkins | Maven | 2.15.1 | |||
| Application | Jenkins | Maven | 2.15 | |||
| Application | Jenkins | Maven | 2.14 |