Vulnerabilities (CVE)

Filtered by vendor Jenkins Subscribe
Filtered by product Mercurial
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-2305 1 Jenkins 1 Mercurial 2020-11-10 4.0 MEDIUM 6.5 MEDIUM
Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2306 1 Jenkins 1 Mercurial 2020-11-06 4.0 MEDIUM 4.3 MEDIUM
A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations.
CVE-2018-1000112 1 Jenkins 1 Mercurial 2019-10-03 5.0 MEDIUM 5.3 MEDIUM
An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and earlier in MercurialStatus.java that allows an attacker with network access to obtain a list of nodes and users.