CVE-2019-20343: Mojohaus Exec Maven

Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.

The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executable element (and can also specify arbitrary command-line arguments in an arguments element).

Affected products

Published 2020-01-06. Last modified 2026-06-17.