CVE-2019-10337: Jenkins Token Macro

High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.

An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks.

Affected products

  • Jenkins Token Macro: up to and including 2.7

Published 2019-06-11. Last modified 2026-06-17.